Privacy Policy

Helsa
Last updated: December 15, 2025 | Version 1.2

Summary: Helsa collects your health data to allow you to store and manage it. Data is encrypted, securely synchronized on our servers, and never sold to third parties. We use third-party services for authentication, storage, payments, and error monitoring.

1. Data Controller

The Data Controller for personal data processing is:

Marino Panariello
Email: marinopanariello@gmail.com
Address: Via Alcide De Gasperi 49, Torre del Greco (NA), Italy

2. Categories of Data Collected

2.1 Account Data

DataPurposeLegal BasisRequirement
Email addressRegistration, login, service communicationsContractRequired
Password (bcrypt hash)Secure authenticationContractRequired
First/Last namePersonalization, document headersContractOptional
Apple ID / Google IDSocial authentication (if used)ContractOptional

2.2 Health Data (Special Categories under Art. 9 GDPR)

Sensitive Data: The documents you upload may contain information related to your health. This data is processed exclusively to provide you with the requested service, based on your explicit consent given at the time of registration.
CategoryExamplesRetention
Medical documentsReports, prescriptions, medical records, testsUntil user deletion
AttachmentsPDFs, images of medical documentsUntil user deletion
Medical appointmentsDate, location, doctor, specialty, notesUntil user deletion
Medications and therapiesDrug name, dosage, frequency, remindersUntil user deletion
Family profilesName, date of birth, family relationshipUntil user deletion

2.3 Technical Data (Automatically Collected)

DataPurposeRetention
Device type, model, OSCompatibility, debugging90 days
App versionSupport, updates90 days
IP addressSecurity, server geolocation30 days
Error logs (crash reports)Debugging, stability improvement90 days
Access timestampsSecurity, audit1 year
Anonymous identifiersAggregate analytics2 years

2.4 Payment Data

Helsa does not store credit card or payment method data directly. Payments are handled by:

  • Apple App Store - for iOS users
  • Google Play Store - for Android users
  • RevenueCat - for cross-platform subscription management

We only receive confirmation of payment and subscription status (active/expired).

3. Purposes and Legal Bases for Processing

PurposeLegal Basis (GDPR)Data Involved
Service delivery (storage, sync, reminders)Art. 6.1.b - Contract performanceAccount, documents, appointments, medications
Health data processingArt. 9.2.a - Explicit consentAll health data
Subscription and billing managementArt. 6.1.b - Contract performanceEmail, subscription status
Service communications (security, critical updates)Art. 6.1.b - Contract performanceEmail
Error monitoring and app stabilityArt. 6.1.f - Legitimate interestTechnical data, crash reports
Analytics and service improvementArt. 6.1.a - ConsentAnonymized usage data
Legal and tax complianceArt. 6.1.c - Legal obligationTransaction data

4. Third-Party Services (Sub-processors)

To provide the service, we use the following technology providers:

4.1 Supabase Inc.

RoleCloud database, authentication, file storage
Data processedAll user data (encrypted)
LocationUSA (with EU server option - Frankfurt)
SafeguardsSOC 2 Type II, GDPR DPA, Standard Contractual Clauses
Privacy Policysupabase.com/privacy

4.2 PostHog Inc.

RoleProduct analytics and user behavior analysis
Data processedApp usage events, anonymized user ID, device info, in-app actions
LocationUSA with EU server (eu.i.posthog.com)
SafeguardsSOC 2 Type II, GDPR compliant, Data Processing Addendum
Privacy Policyposthog.com/privacy

Details on PostHog usage:

  • We use EU servers to ensure data remains within the European Union
  • We collect app lifecycle events (open, close, background)
  • Events are aggregated and anonymized
  • We do not collect document contents or health data through analytics
  • You can request deletion of your analytics data by contacting us

4.3 Sentry (Functional Software Inc.)

RoleError monitoring and crash reporting
Data processedStack traces, device info, anonymized user ID
LocationUSA (EU servers available)
SafeguardsSOC 2 Type II, GDPR DPA, Data Processing Addendum
Privacy Policysentry.io/privacy

4.4 RevenueCat Inc.

RoleIn-app subscription management
Data processedUser ID, subscription status, purchase receipts
LocationUSA
SafeguardsGDPR compliant, DPA available
Privacy Policyrevenuecat.com/privacy

4.5 Apple Inc. / Google LLC

RoleApp distribution, in-app payments, social authentication
Data processedApple/Google account (if used for login), transactions
Privacy PolicyApple Privacy | Google Privacy

4.6 Expo / React Native (Meta)

RoleDevelopment framework, push notifications, OTA updates
Data processedPush token, diagnostic data
Privacy Policyexpo.dev/privacy

5. Data Transfers Outside the EU

Some of our providers are based in the United States. Data transfers comply with GDPR through:

  • Standard Contractual Clauses (SCC) - Standard contractual clauses approved by the European Commission
  • EU-US Data Privacy Framework - For certified providers
  • Binding Corporate Rules - Where applicable

You can request a copy of the appropriate safeguards by contacting us at the email address provided.

6. Data Retention

CategoryRetention PeriodAfter Account Deletion
Account dataDuration of contractual relationshipDeleted within 30 days
Documents and attachmentsUntil deleted by userDeleted within 30 days
Backups30 days (rolling backup)Purged within 60 days
Technical logs90 daysN/A (anonymized)
Analytics data (PostHog)2 yearsAnonymized/deleted upon request
Billing data10 years (tax requirement)Retained for legal obligation
Consent and audit trail5 years from last interactionRetained for legal protection

7. Data Security

We implement appropriate technical and organizational measures:

Encryption

  • TLS 1.3 for all communications in transit
  • AES-256 for data at rest in the database
  • Bcrypt hashing for passwords
  • Expo SecureStore for device tokens

Access Control

  • Row Level Security (RLS) on database
  • JWT authentication with refresh tokens
  • Optional biometric authentication (Face ID/Touch ID)
  • Automatic session timeout

Infrastructure

  • Servers in certified data centers (SOC 2, ISO 27001)
  • Automatic daily backups
  • 24/7 monitoring with alerting
  • Disaster recovery plan

Access to Your Files

Privacy by Design: The files you upload (documents, reports, images) are protected. Our team will not access your data without a legitimate reason.

We have implemented technical and organizational measures to protect your health files:

  • Row Level Security (RLS): Each file is accessible exclusively by the owner through their own JWT authentication
  • Access restrictions: Administrative access to user content is strictly limited and controlled
  • Audit trail: Every data access is tracked and verifiable

We may access your data only for:

  • Providing technical support at your request
  • Account recovery assistance
  • Investigating security incidents or abuse
  • Complying with legal obligations (e.g., court orders)

For routine technical support, we typically only view:

  • File metadata (name, creation date, size)
  • Synchronization status
  • Application error logs (without file content)
  • Aggregate counts and statistics

This architecture ensures that your health data remains private during normal operations and technical support requests.

8. Your Rights (Art. 15-22 GDPR)

As a data subject, you have the right to:

RightDescriptionHow to Exercise
Access (Art. 15)Obtain confirmation of processing and a copy of your dataEmail or in-app function
Rectification (Art. 16)Correct inaccurate or incomplete dataDirectly in-app or email
Erasure (Art. 17)Request deletion of your data ("right to be forgotten")Settings → Delete account
Restriction (Art. 18)Restrict processing in certain circumstancesEmail
Portability (Art. 20)Receive your data in a structured format (JSON/CSV)Settings → Export data
Objection (Art. 21)Object to processing based on legitimate interestEmail
Withdraw consent (Art. 7)Withdraw consent at any timeSettings or email

We will respond within 30 days of the request. For complex requests, the deadline may be extended by an additional 60 days with prior notice.

9. Account and Data Deletion

You can request complete deletion in two ways:

  1. In-app: Settings → Account → Delete account
  2. Email: Write to marinopanariello@gmail.com

Deletion involves:

  • Irreversible deletion of all documents and attachments
  • Removal of data from servers within 30 days
  • Purging of backups within 60 days
  • Retention only of data required for legal obligations

10. Minors

Helsa is not intended for minors under 16 years of age. We do not knowingly collect data from minors under 16 without verifiable consent from a parent or guardian.

If you are a parent and believe your child has provided personal data, please contact us immediately for removal.

11. Cookies and Tracking Technologies

The mobile application does not use cookies in the traditional sense. We use:

  • SecureStore: To securely store authentication tokens on the device
  • AsyncStorage: For user preferences and local cache
  • SQLite: For offline document storage
  • PostHog SDK: For product analytics (with EU servers)

For more details, see our Cookie Policy.

12. Changes to the Privacy Policy

We reserve the right to update this policy. In case of substantial changes:

  • We will send you an in-app notification
  • We will send you an email (if you have an account)
  • We will update the "Last updated" date
  • For changes requiring new consent, we will explicitly request it

13. Complaints

If you believe the processing of your data violates the GDPR, you have the right to file a complaint with:

Italian Data Protection Authority (Garante per la Protezione dei Dati Personali)
Piazza Venezia 11 - 00187 Rome, Italy
Email: protocollo@gpdp.it
PEC: protocollo@pec.gpdp.it
Website: www.garanteprivacy.it

14. Contact

For privacy-related questions:

Email: marinopanariello@gmail.com

Data Controller:

Marino Panariello
Via Alcide De Gasperi 49, Torre del Greco (NA), Italy
Email: marinopanariello@gmail.com

© 2024 Helsa. All rights reserved.

This policy has been drafted in compliance with EU Regulation 2016/679 (GDPR).