Privacy Policy
Last updated: June 2025
Who We Are
This privacy policy applies to the IBDi app and website (https://ibdi.se). IBDi is a digital tool developed for a clinical study on Ulcerative Colitis (UC) self-management, coordinated by Lunds Universitet and Skånes universitetssjukhus.
For questions, contact us at contact@ibdi.se.
For GDPR matters, contact Region Skåne’s Data Protection Officer.
What Personal Data We Collect and Why
We collect and process the following data only from study participants:
- Email address (required)
- Phone number (optional, for SMS reminders)
- App usage data, including:
- Fecal calprotectin test results
- SCCAI symptom surveys
- Medication adherence logs
No location or financial data is collected.
Purpose of Data Processing
Data is collected exclusively to support:
- Participation in the HULC clinical study
- Digital self-monitoring and communication with healthcare staff
- Research on remote UC care models
Legal Basis
We process your personal data based on:
- Informed consent (signed upon enrollment)
- Public interest in scientific research (GDPR Art. 6(1)(e), 9(2)(j))
Who Has Access to Your Data
Your data is only shared with:
- Doctors and nurses involved in the HULC study
- The study’s research team at Lunds Universitet and Region Skåne
- Third-party service providers listed below
Third-Party Services
We use the following GDPR-compliant services:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (EU) | Secure data storage | EU 🇪🇺 |
| Firebase (Google) | User authentication | EU 🇪🇺 |
| Brevo (formerly Sendinblue) | Email and SMS communication | EU 🇪🇺 |
How We Protect Your Data
- All data is encrypted in transit and at rest
- User access is authenticated via Firebase
- Access is limited to authorized healthcare staff and researchers
- No data is transferred outside the EU
Data Retention
Data is retained:
- During your participation in the study
- For 15 years after study completion, in line with Swedish research regulations
Your Rights Under GDPR
You have the right to:
- Access your data
- Correct inaccurate data
- Request deletion from the app and database
- Withdraw consent at any time
- Contact the Swedish Authority for Privacy Protection (IMY)
To exercise any of these rights, email contact@ibdi.se
Data Deletion
If you withdraw from the study or request deletion, your data will be removed from the app and database. However, your study clinicians may still retain relevant medical records per Swedish law.
Children’s Data
The IBDi app is not intended for use by individuals under 18 years old.
Changes to This Policy
This policy may be updated. Significant changes will be posted on https://ibdi.se and notified via the app or email.