The purpose of this Privacy Notice (“Notice”) is to describe how mama health technologies GmbH (“mama health technologies” “we”, “us”, “our”) collects, uses and shares information about you through our mama health patient app (“mama health” “platform” “app”) in accordance with applicable data protection and privacy laws.
Please read this Notice carefully to understand what we do. If you do not understand any aspects of this Notice please feel free to contact us at the address indicated at the end of this Notice.
"mama health patient app", “mama health Platform”, “Platform” or “Service” is an AI educational tool that collects and analyses information from users suffering from specific medical conditions, in order to provide personalized answers and educational content. The answers provided by the tool are based on medically validated sources and the experience of other users. The use of the platform is strictly educational, and therefore not intended to be used for medical purposes.
“User”, “Data Subject” refers to the identifiable natural person using the mama health platform to whom the Personal Data and Sensitive Data refers.
“Personal Data” or “Personal Information” refers to any information that directly, indirectly, or in connection with other information allows for the identification of the User .
“Pseudonymized Data” refers to Personal Data that can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Anonymous Data" refers to information which does not relate to an identified or identifiable natural person.
"Anonymized Data" refers to user data rendered anonymous in such a manner that the recipient is not reasonably able to identify the data subject, taking into account all means reasonably likely to be available to the recipient.
“Applicable Privacy Laws” refers to all applicable laws and regulations, including laws and binding regulations of the European Union and their member states, Switzerland, the United Kingdom, the United States of America and Canada that apply to the Processing of Personal Data by mama health when providing the mama health Platform to users in different countries.
“Processing” refers to any operation or set of operations which is performed on Personal Data.
“Controller” refers to the person or legal entity responsible for determining the purpose and means of the Processing of your Personal Data.
“Processor” refers to an individual or legal entity that processes Personal Data on behalf of a Controller.
“Sensitive Personal Information”, “Sensitive Data” or “Special categories of Personal Data” refers to any Personal Information that reveals information considered sensitive according to the Applicable Privacy Law (e.g.:data concerning health).
We collect and use your information listed in “INFORMATION WE COLLECT” and only for the purposes listed in this Privacy Notice.
Personal Data is collected and processed only in accordance with the relevant legal basis as mandated by the Applicable Privacy Laws.
This Notice details the processing of personal information gathered through your use of our Platform.
This Notice does not cover information collected outside of the mama health Platform, including data from other services provided by mama health technologies GmbH, such as our website and any third party services.
This Notice does not apply to the processing of anonymous data, however it covers the process of anonymization of personal data.
As set forth in the Terms of Use, you must be at least sixteen (16) years old to use or access the Platform. If you are under the age of 16, please do not attempt to register with us at this Platform or provide any personal information about yourself to us. If we learn that we have collected personal information from a child under the age of 16, we will promptly delete that information. If you believe we might have any information from a child under the age of 16, please Contact Us at privacy@mamahealth.com
The Data Controller for any Personal Information processed in connection with our Platform is:
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
mama health technologies GmbH will process the following categories of personal data of users:
| Categories of personal data | Special category of data | Examples of data processed |
|---|---|---|
| Common data - Physical characteristics | No | gender |
| year of birth | ||
| Common data - Other Personal | No | appointments booked |
| feedback given | ||
| feedback rating (stars) | ||
| Common data - Home&Family | No | country of residence and postal code |
| Common data - Usage data | No | access token |
| app settings | ||
| cookies | ||
| device information | ||
| language | ||
| usage logs, crashes, errors | ||
| Identifiers - Personal Information | No | e-mail address |
| name | ||
| voice (if users choose to record their input via microphone) | ||
| Identifiers - Online | No | IP address |
| Health information | Yes | chat content (patient's history - kind of anamnesis guided by AI chatbot) |
| chat content ( Questions section - Q&A based patients shared experiences) | ||
| current symptoms - type of disease - symptom's impact on daily life (scale value) - current treatments - official diagnosis (yes/no) - challenges in managing disease | ||
| dashboards (statistics about patient's condition) | ||
| tailored report based on the health information shared by users | ||
| uploaded medical documentation (images or files) | ||
| voice (Chat content - patient's history - kind of anamnesis guided by AI chatbot) |
Personal Information is collected:
When you register on our Platform
When you use and interact with our Platform
When you contact us for support or any inquiries
On your account information page
We process your Personal Information in order to provide you with our platform and its main functionalities. These include the following activities:
Account creation and management, including the collection of the necessary information to access the Service;
Chat content collection, storage and further elaboration;
Collection of browsing and traffic data to ensure the stability and security of the system;
Anonymization and Aggregation of User data for creating Insights to be used in the app and shared with our third party business partners. The aggregated data is used to create dashboards showing trends in patient pathways, common symptoms, and treatment journeys. Our business partners access only anonymized, statistical views of the data;
Collecting users' feedback and inquiries to address any issues and improve our Service;
Sending communications with general information and updates about the Platform;
Prevent unauthorized access, unlawful use or fraud and detect anomalies on our Platform.
Your Personal Information will only be processed if we have a legitimate ground to do so. For a more detailed description of each purpose and processing activity and the connected legal grounds, please consult the table available under "1. Processing under the EU's GDPR - Why do we process your data".
We may process your personal information because:
We need to provide you with the requested Service and honor our contractual obligations with you;
You have given us your consent to do so. We will only process your sensitive data on the basis of your consent;
The processing is in our legitimate interest and it is not overridden by your rights. We may have a legitimate interest in ensuring platform security (prevent unauthorized access, fraud and detect any anomalies), as well as in addressing your inquiries and any flagged issues regarding the App in order to improve our Service, and to send you communications with general information about the Platform;
To comply with applicable laws and regulations we may be subject to.
We may share your Personal Information with our employees and trusted business partners when necessary to fulfill the purposes outlined in this Privacy Notice.
Recipients may include, for example:
Third-party IT service providers who help operate and host our Platform and Services;
Third parties involved in complying with legal obligations, or establishing, exercising, or defending rights or claims (such as courts, regulators, law enforcement, government authorities, attorneys, and consultants);
Third party business partners with whom we share anonymized and aggregated insights resulting from the anonymization of the data we collect when you use our Platform. These third parties will not have access to your personal data but only to the aggregated and anonymized information derived from your data.
These third parties will have access to your personal information to perform their services. When this occurs, we implement reasonable contractual and technical safeguards to limit their use of the information solely for the purpose of providing the contracted service. When our service providers act as Data Processors, we will ensure that they only process your personal data under appropriate confidentiality and security obligations and in accordance with our instructions and with this Notice.
Note that the recipients of your Personal Data may be located outside of your country of residence. Further details on international transfers of Personal Data are available in the dedicated section of the Privacy Notice applicable to you.
We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.
The security of your Personal Information is important and we are committed to protecting the information we collect. We maintain reasonable administrative, technical and physical safeguards designed to protect the Personal Information you provide or we collect against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use.
In the event of a breach of our security safeguards, we will assess the extent of harm (if any) to individuals, and comply with reporting and notification obligations in accordance with the applicable law.
We also take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.
If you have any questions about personal information we have about you or need to update your information, or wish to unsubscribe, you can contact us at the contact details provided in the Contact Us section at the end of this Notice.
For more detailed information on your data protection rights and how to exercise them please consult the dedicated section that applies to your country of residence.
This section applies and provides you with further information if you are located within the European Economic Area in accordance with the EU General Data Protection Regulation 679/2016 ("GDPR").
Only for the purposes mentioned under section “why do we process your data” the Data Controller is:
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
If you have any questions related to how we process your personal data you can contact us at any time by sending an email to: privacy@mamahealth.com
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
We will process your personal data for the following purposes:
| Purpose | Activities | Legal basis (art. 6 and art. 9) | Provision of personal data | Data Categories |
|---|---|---|---|---|
| Analysing user behaviour |
TBC Analysing user behaviour
We use cookies and other tracking technologies to analyse and understand how users interact with our app. |
|
These data will only be processed if you consented to the setting of cookies in the cookie banner. You can withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of the processing prior to the withdrawal. | Common data - Usage data |
| Identifiers - Online | ||||
| Anonymization and Aggregation of Patient Data for Research Insights |
Anonymization and Aggregation of Patient Data for creating Insights to be used in the app and shared with third parties
Patient-provided data is anonymized and aggregated to generate insights to be used within the patient app and for third party pharmaceutical companies. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. The aggregated data is used to create dashboards showing trends in patient pathways, common symptoms, and treatment journeys. Our Third party business partners access only anonymized, statistical views of the data. Additionally, they can interact with an AI tool to explore these insights without accessing raw or identifiable data. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Health information | ||||
| Communicating with users |
Sending of communications
We may send you e-mail from time to time with generic information and suggestions to help you use our Platform and its functionalities, or inform you about any updates or new features. |
|
Your data is processed automatically when you successfully create an account. You can object to the processing at any time and unsubscribe from these communications. | Common data - Usage data |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Ensure platform security |
Collection of browsing and traffic data to ensure system security
We automatically collect browsing and usage data in order to prevent unauthorised access, unlawful use or fraud and detect anomalies on our Platform. |
|
These data are collected automatically when you use our platform. In any case, you can object to the processing at any time. | Common data - Usage data |
| Identifiers - Online | ||||
| Processing users' feedback and inquiries about the service |
Processing users' feedback and inquiries
Users can leave a star-rating or a feedback message in the app to let mama health know their opinion on the app. Users can also choose to contact us via e-mail for any inquiries or they can book an appointment via Calendly with one of our employees to discuss any aspects of the app. Users can choose to share any personal data, including sensitive information on a voluntary basis. We will process users' feedback and requests to address any existing issues and improve our service. |
|
Your data will only be processed if you decide to leave a feedback or get in touch with us. | Common data - Other Personal |
| Identifiers - Personal Information | ||||
| Provision of the service to patients |
Account creation and management
In order to be able to use our platform, users need to create a profile that reflects their condition. To complete registration, users need to provide their name and email address, country of residence and year of birth and also health related information including their current symptoms, treatments, diagnosis, health insurance and difficulties in managing their health condition. Once an account has been created, users can log in again by providing their e-mail address and the access token they receive per e-mail. Users can also log in via Google/Apple Sign-in. |
|
The provision of your data is necessary in order to access and use our platform. For special categories of data (health information), we rely on your explicit consent to process this data. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Chat content collection, storage and further elaboration
Through an AI chatbot, patients are guided to share their symptom story, much like a doctor's anamnesis. This conversational interaction allows patients to provide relevant information, including through voice input and document uploads (e.g., doctor's letters). Once the anamnesis is completed, the shared information personalizes the platform's Q&A functionality, enabling patients to ask questions that are informed by their unique health narrative. All answers provided will include sources. |
|
The provision of your data is necessary in order to use the chatbot function of the platform. For special categories of data (health information), we rely on your explicit consent to process this data, you can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Identifiers - Personal Information | |
| Identifiers - Online | ||||
| Health information | ||||
|
Dashboard creation
Once the anamnesis is complete, the app generates a dashboard. The "analysis" dashboard provides users with an overview of key statistics related to their condition with personalized insights based on the available information. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Common data - Physical characteristics | |
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Detailed report generation
At any point, users can access the "Report" section of the app and download their tailored report generated by AI based on the data provided to the chatbot as well as the information provided during onboarding. Users can update their information with every new entry in the chatbot and download the updated PDF. Users are advised that the Report is generated using AI models that elaborate the information provided and these may contain errors and are only provided for informational purposes. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Health information |
Your personal data will be processed primarily within the European Union and the European Economic Area. Should we transfer data to service providers or other third parties outside the EU/EEA, such data transfers will take place only to third countries with an Adequacy Decision in place approved by the European Commission or, in case of no Adequacy Decision, based on Standard Contractual Clauses provided by the European Commission and additional security measures to ensure data security.
We will retain your personal data only as long as necessary to fulfill the purposes for which we collected it, including purposes related to fulfilling legal, tax or accounting obligations.
A longer retention period may be required in the event of a legal complaint or in the event of disputes related to our existing contractual relationships.
To determine the retention period of personal data, we take into account:
If personal data is no longer necessary for the purposes or legitimate interests pursued by us, and no other legal basis applies, we will delete your data.
We inform you that you have the right to:
The exercise of rights is not subject to any formal constraints and is free of charge.
You may exercise your rights by contacting us at the following address privacy@mamahealth.com
Your competent data protection authority
In case of data privacy related concerns and requests, we encourage you to contact us at privacy@mamahealth.com. You also always have the right to approach the competent data protection authority with your request or complaint.
A list and contact details of local data protection authorities is available here.
This section applies and provides you with further information if you are located within the United Kingdom under the Data Protection Act 2018 and/or the UK GDPR (meaning Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018)
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
As we do not have a physical establishment in the UK, we have appointed Data Protection Representative Limited (trading as DataRep) as our Representative in the UK for the purposes of Article 27 UK GDPR.
Please note when mailing inquiries, it is essential that you mark your letters for “DataRep” and not “mama health technologies GmbH” for it to reach us.
We will process your personal data for the following purposes:
| Purpose | Activities | Legal basis (art. 6 and art. 9) | Provision of personal data | Data Categories |
|---|---|---|---|---|
| Analysing user behaviour |
TBC Analysing user behaviour
We use cookies and other tracking technologies to analyse and understand how users interact with our app. |
|
These data will only be processed if you consented to the setting of cookies in the cookie banner. You can withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of the processing prior to the withdrawal. | Common data - Usage data |
| Identifiers - Online | ||||
| Anonymization and Aggregation of Patient Data for Research Insights |
Anonymization and Aggregation of Patient Data for creating Insights to be used in the app and shared with third parties
Patient-provided data is anonymized and aggregated to generate insights to be used within the patient app and for third party pharmaceutical companies. Identifiable information is removed, and relevant medical details (e.g. symptoms, medications, side effects) are extracted from patient narratives. Any residual identifiers in chat data are also deleted. An aggregation threshold is applied. The aggregated data is used to create dashboards showing trends in patient pathways, common symptoms, and treatment journeys. Our Third party business partners access only anonymized, statistical views of the data. Additionally, they can interact with an AI tool to explore these insights without accessing raw or identifiable data. Uploaded documents are parsed for relevant text, which may be included in the analysis. Original medical documents (e.g., doctor reports) are retained in the database, but not altered. Data within the patient interface is not processed for this purpose and is only used to support patient follow-up queries. |
|
These data will only be processed if you give your explicit consent. You can withdraw your consent at any time without affecting the lawfulness of the processing prior to the withdrawal of consent. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Health information | ||||
| Communicating with users |
Sending of communications
We may send you e-mail from time to time with generic information and suggestions to help you use our Platform and its functionalities, or inform you about any updates or new features. |
|
Your data is processed automatically when you successfully create an account. You can object to the processing at any time and unsubscribe from these communications. | Common data - Usage data |
| Identifiers - Personal Information | ||||
| Identifiers - Online | ||||
| Ensure platform security |
Collection of browsing and traffic data to ensure system security
We automatically collect browsing and usage data in order to prevent unauthorised access, unlawful use or fraud and detect anomalies on our Platform. |
|
These data are collected automatically when you use our platform. In any case, you can object to the processing at any time. | Common data - Usage data |
| Identifiers - Online | ||||
| Processing users' feedback and inquiries about the service |
Processing users' feedback and inquiries
Users can leave a star-rating or a feedback message in the app to let mama health know their opinion on the app. Users can also choose to contact us via e-mail for any inquiries or they can book an appointment via Calendly with one of our employees to discuss any aspects of the app. Users can choose to share any personal data, including sensitive information on a voluntary basis. We will process users' feedback and requests to address any existing issues and improve our service. |
|
Your data will only be processed if you decide to leave a feedback or get in touch with us. | Common data - Other Personal |
| Identifiers - Personal Information | ||||
| Provision of the service to patients |
Account creation and management
In order to be able to use our platform, users need to create a profile that reflects their condition. To complete registration, users need to provide their name and email address, country of residence and year of birth and also health related information including their current symptoms, treatments, diagnosis, health insurance and difficulties in managing their health condition. Once an account has been created, users can log in again by providing their e-mail address and the access token they receive per e-mail. Users can also log in via Google/Apple Sign-in. |
|
The provision of your data is necessary in order to access and use our platform. For special categories of data (health information), we rely on your explicit consent to process this data. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Common data - Physical characteristics |
| Common data - Home&Family | ||||
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Chat content collection, storage and further elaboration
Through an AI chatbot, patients are guided to share their symptom story, much like a doctor's anamnesis. This conversational interaction allows patients to provide relevant information, including through voice input and document uploads (e.g., doctor's letters). Once the anamnesis is completed, the shared information personalizes the platform's Q&A functionality, enabling patients to ask questions that are informed by their unique health narrative. All answers provided will include sources. |
|
The provision of your data is necessary in order to use the chatbot function of the platform. For special categories of data (health information), we rely on your explicit consent to process this data, you can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Identifiers - Personal Information | |
| Identifiers - Online | ||||
| Health information | ||||
|
Dashboard creation
Once the anamnesis is complete, the app generates a dashboard. The "analysis" dashboard provides users with an overview of key statistics related to their condition with personalized insights based on the available information. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Common data - Physical characteristics | |
| Common data - Usage data | ||||
| Identifiers - Personal Information | ||||
| Health information | ||||
|
Detailed report generation
At any point, users can access the "Report" section of the app and download their tailored report generated by AI based on the data provided to the chatbot as well as the information provided during onboarding. Users can update their information with every new entry in the chatbot and download the updated PDF. Users are advised that the Report is generated using AI models that elaborate the information provided and these may contain errors and are only provided for informational purposes. |
|
The provision of your data is necessary in order to use this function and your data is collected and analyzed automatically by us. For special categories of data (health information), we rely on your explicit consent for processing. You can withdraw your consent at any time without affecting the lawfulness of the processing until that point, but this would also affect our ability to further provide you with the service. | Health information |
In the event that we transfer your personal data outside the United Kingdom, we ensure that your data is protected in a manner which is consistent with the UK GDPR. Therefore, and if required by applicable law, appropriate safeguards are implemented, which typically include: relying on an adequacy decision from the UK authorities; using the European Commission’s standard contractual clauses (with required UK addendums); or ensuring the transfer is covered by an approved framework like the EU-US Data Privacy Framework with the UK extension. Technical and organizational measures are also taken where necessary to ensure data remains protected during the transfer.
We inform you that you have the right to:
The exercise of rights is not subject to any formal constraints and is free of charge.
You may exercise your rights by contacting us at the following address privacy@mamahealth.com
You have the right to submit a complaint at any time to the Information Commissioner’s Office (ICO), the UK data protection supervisory authority (www.ico.org.uk).
If you are located in Switzerland, mama health technologies GmbH (controller, we, us), processes your personal data as a Data Controller in accordance with the Swiss Federal Act on Data Protection (FADP).
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
As we do not have a physical establishment in Switzerland, we have appointed Data Protection Representative Limited (trading as DataRep) as our Representative in Switzerland in accordance with Art. 14 of the Swiss Federal Act on Data Protection (FADP).
Please note when mailing inquiries, it is essential that you mark your letters for “DataRep” and not “mama health technologies GmbH” for it to reach us.
We may transfer some of your personal data to service providers based other countries, such as Germany and the USA. We ensure that your data is only disclosed outside of Switzerland if an appropriate level of data protection is guaranteed by one of the following safeguards: a treaty under international law; data protection clauses in an agreement with our contractual partners; specific guarantees drawn up by the competent federal body; standard data protection clauses that the FDPIC has approved, issued or recognized beforehand.
In accordance with the FADP, you have the right to:
You may exercise your rights as set out in the FADP by contacting the Data Controller at: privacy@mamahealth.com
You also have the right to submit a complaint at any time to the Federal Data Protection and Information Commissioner (FDPIC), the Swiss data protection authority (https://www.edoeb.admin.ch).
If you are a U.S. resident and to the extent where we are subject to U.S. state privacy laws in the context of the provision our platform, the following additional data protection safeguards shall apply:
We may process Personal Information concerning the past, present, or future physical or mental health status of Washington State residents (consumer health data), making it subject to the provisions of the Washington My Health My Data Act (hereinafter MHMD Act). The information included in this Notice describes the collection of consumer health data as mandated by the MHMD Act, including the indication of consent as a legal basis, which is equally applicable for purposes of the MHMD Act. In addition to the privacy rights outlined below, Washington state residents may have the following rights:
to confirm whether we are collecting, sharing, or selling consumer health data concerning them and to access such data, including a list of all third parties and affiliates with whom we shared or sold the consumer health data and an active email address or other online mechanism that the consumer may use to contact these third parties.
to withdraw consent from our collection and sharing of consumer health data concerning the consumer.
to have consumer health data concerning them deleted and exercise that right by informing us of their request for deletion.
You may exercise these rights by submitting a request to mama health at the contact details provided in the Contact Us section of this Notice. We may request additional information from you to authenticate your request.
We will not discriminate against you should you decide to exercise your consumer rights under the Act.
Where applicable, mama health complies with the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Acts of 2020 (CPRA) (hereinafter CCPA) requirements concerning the exercise of your rights and with other U.S. state laws with similar requirements. We provide the following rights to all residents of the U.S., regardless of where they live:
Right to Opt-Out of Third-Party Sales and Sharing of their personal data
Right to request disclosure of their personal information obtained during the previous 12 months.
Right to request deletion of personal information if it is no longer required to satisfy one of the objectives specified in Cal. Civ. Code Sec. 1798.105
Right to obtain a copy of their personal information and request to transfer certain information to another organization.
Right to request that any incorrect personal information concerning them provided by a company be corrected.
Right to restrict the usage and disclosure of their sensitive personal information to “use that is necessary to execute the services or deliver the products reasonably expected by an ordinary consumer who requests such goods and services.”
Right to obtain “meaningful information about the logic involved” in automated decision-making processes, as well as a description of the process’s expected outcome with respect to the consumer.
Right to Opt-Out of Automated Decision-Making Technology.
You can exercise your rights by submitting a request via email or per post at the contact details provided in the Contact Us section of this Notice.
If you are a resident of Canada, we respect your privacy and ensure your Personal Information is protected in accordance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and any applicable provincial privacy laws, such as those in Alberta ("Personal Information Protection Act of Alberta", or “PIPA Alberta”), British Columbia ("Personal Information Protection Act of British Columbia" or “PIPA BC”), and Quebec ("Act Respecting the Protection of Personal Information in the Private Sector" or “Quebec Private Sector Act”).
The information provided in this Privacy Notice applies to the processing of personal information of residents of Canada; in addition to that, the following applies:
mama health technologies GmbH with registered address in August-Bebel-Straße 88, 14482 Potsdam is accountable for the Personal Information under our control.
To further strengthen your data protection, we've appointed a dedicated Data Protection Officer (DPO), who you can contact if you have any questions about how your personal data is processed, or if you believe your privacy rights may have been infringed.
You can contact our DPO by sending an email to: dpo@mamahealth.com
We are committed to safeguarding your data, however, providing sensitive data (health related information about you) carries inherent residual risks due to its nature, such as unauthorized access or data breaches, which we mitigate through strict security safeguards.
Please note that, as we are based in the EU we might transfer your personal data outside of Canada for processing, where it may also be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. To ensure that an appropriate level of data protection is guaranteed, and if required by applicable law, we implement appropriate safeguards when transferring personal data.
Under Canadian law, valid consent means you understand the nature, purpose, and consequences of how your data is collected, used, or disclosed.
Where our Processing is based on your consent under the GDPR, this is also considered valid consent under Canadian federal and provincial laws. Where we rely on our legitimate interest or legal requirements under the GDPR, this Notice serves as notice for your deemed or implicit consent under laws like PIPA Alberta and PIPA BC.
The following rights are granted in addition to your rights as a Data Subject under the GDPR. Where you exercise both your GDPR and Canadian data protection rights simultaneously, mama health technologies GmbH will guarantee those rights in addition to each other.
You have the right to challenge the accuracy and completeness of your Personal Information and request access to the data we hold about you.
Accessing Your Data: You may request to know what Personal Information we have, how it is used, and to whom it has been disclosed. We will respond to your written request as quickly as possible and no later than 30 days, providing access at minimal or no cost.
Correcting Your Data: If your information is inaccurate or incomplete, you may request that we amend it. We will update the data and, where appropriate, send the corrected information to any third parties who have access to it.
Withdrawing consent: You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal
How to Exercise These Rights: To submit an access or correction request, please contact us at the address indicated in the "Contact us" section of this Notice.
If you have any concerns regarding how mama health technologies GmbH handles your Personal Information, you have the right to challenge our compliance. We have simple complaint handling procedures in place and will investigate all complaints.
If you are unsatisfied with our internal resolution, you also have the right to escalate your complaint to the relevant regulatory bodies, including the Office of the Privacy Commissioner of Canada (OPC), or the applicable provincial privacy commissioner in Alberta, British Columbia, or Quebec.
You can contact us at any time at the following email address: privacy@mamahealth.com
Alternatively, you can also reach us per mail at: privacy@mamahealth.com
mama health technologies GmbH
August-Bebel-Straße 88, 14482 Potsdam
mama health patient app may contain links to websites operated by third parties. We are not responsible and have no control over how they operate or how they process data. We encourage you to read their privacy notices before using those websites.
Cookies are small text files stored on users' devices by the server of the website they are visiting and contain information about the user's navigation that can be read by the same server in subsequent browsing sessions. Cookies do not harm the device and enable a better browsing experience.
Our solution uses cookies. To know more please consult our Cookie Policy.
This Notice may be subject to changes and reviews.
All personal data processed is subject to this Privacy Notice effective at the time it was collected.
Any changes to this Notice will be posted on this page and, if necessary, notified to you.
We encourage you to consult our Notice periodically so that you are always informed about how we process your personal data.
This Privacy Notice was last updated on 28/04/2026