Privacy Policy — MyCare@HOME App
Effective Date: 29 September 2026 Last Updated: 29 September 2026
Introduction
Giulia Indemini (“we,” “our,” or “us”) operates the MyCare@HOME mobile application (the “App” or “Service”).
This Privacy Policy describes how we collect, use, disclose, and protect personal data when you use our App. It applies exclusively to the MyCare@HOME mobile application and the data processed through it. The privacy policy for the mycareathome.ch website is published separately.
By using MyCare@HOME, you agree to the collection and use of information in accordance with this policy.
1. Data Controller
The data controller for personal data processed through the App is:
Giulia Indemini In Campii 36 6673 Maggia, Switzerland Email: support@mycareathome.ch
For any questions regarding the processing of your personal data, please contact us at the email address above.
2. Applicable Law
The processing of personal data through this App is governed by:
- The revised Swiss Federal Act on Data Protection (nFADP / LPD), in force since 1 September 2023, and its implementing Ordinance (OPDa / VDSG);
- The principles of the General Data Protection Regulation (GDPR – EU 2016/679) are taken into account by design, in anticipation of potential expansion toward the European Union.
3. Information We Collect
3.1 Account Information
When you register and use MyCare@HOME, we collect:
- Email address
- Full name
- Phone number (optional)
- Professional credentials (for healthcare professional users)
- Role within your healthcare organization
3.2 Organization Information
- Organization name and identifier
- Department or unit affiliation
- Work location
3.3 Health and Assessment Data
Healthcare professional users (Admin, Manager, Caregiver) may enter:
- Patient assessment responses (Wellness Check, Clinical Check)
- Clinical observations and care notes
- Care recommendations
- Assessment scores and results
- Patient names, identifiers, and demographic information
- Date of birth, gender, health insurance number (AVS), medical history
Free Users (personal use) may enter:
- Family member names and demographic information
- Wellness Check assessment responses for family members
- Assessment results and recommended services
Important: All health data entered by healthcare professionals remains under the control of the respective healthcare organization. MyCare@HOME acts as a data processor on their behalf for that data.
3.4 Usage and Technical Data
We automatically collect:
- Device information (model, operating system version)
- App version and build number
- Features used and interaction patterns
- Error logs and crash reports
- Session duration and frequency
- Language preference
- IP address and device identifiers
- Network connection type and app performance metrics
4. How We Use Your Information
We use collected information to:
- Authenticate users and manage accounts
- Enable patient and family member assessment workflows
- Generate clinical and wellness reports (PDF export)
- Synchronize data across devices via Microsoft Azure
- Provide role-based access control
- Analyze usage patterns and improve the App
- Identify and fix bugs and optimize performance
- Send important service and security notifications
- Respond to support inquiries
- Detect and prevent fraud and unauthorized access
- Maintain audit logs
4.1 Legal Basis
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Performance of contract |
| Improving the App | Legitimate interest |
| Security and fraud prevention | Legitimate interest / legal obligation |
| Health data processing | Explicit consent / legal obligation (nFADP Art. 31) |
| Communications | Legitimate interest / consent |
5. Data Storage and Security
5.1 Storage
- Server Storage: All data is hosted on Microsoft Azure infrastructure.
- Local Storage: Authentication tokens are stored securely using iOS Keychain with encryption.
- Backups: Regular encrypted backups are maintained.
5.2 Security Measures
- All data transmitted using HTTPS/TLS encryption
- Sensitive data encrypted at rest
- iOS Keychain for secure local storage
- Database-level encryption
- JWT (JSON Web Token) based authentication
- Secure password hashing
- Automatic session timeout
- Multi-factor authentication (MFA) enabled for all user roles
- Role-based access control (RBAC) with principle of least privilege
- Organization-level data isolation
- Security audit logging and intrusion detection
5.3 Data Retention
- Active accounts: Data retained while the account is active
- Deleted accounts: Personal data deleted within 30 days of account deletion request
- Health records: May be retained longer to comply with applicable Swiss healthcare regulations
- Legal requirements: Some data may be retained for the period required by law
6. Data Sharing and Disclosure
6.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
6.2 Sharing Within Your Organization
Patient data and assessments are accessible only to authorized users within your healthcare organization, based on role and patient assignments. All access is logged.
6.3 Third-Party Service Providers
| Provider | Service | Data Involved | Location |
|---|---|---|---|
| Microsoft Azure | Cloud hosting and data storage | All app data | EU / Switzerland |
| Email service provider | Notifications and MFA codes | Email address | TBD |
All third-party providers are contractually obligated to process data only as instructed, maintain appropriate security measures, and comply with applicable data protection laws.
6.4 Legal Requirements
We may disclose your information if required to comply with legal obligations (court orders, subpoenas), protect our rights and safety, or investigate fraud or security issues.
7. Healthcare-Specific Considerations
7.1 Swiss Data Protection (nFADP)
- Health data is treated as sensitive personal data under the revised Federal Act on Data Protection
- Consent is recorded when a patient or family member is registered
- Access is governed by role-based authorization
- Breach notification procedures are in place in accordance with nFADP requirements
7.2 GDPR (European Union)
For EU healthcare organizations:
- Data Processing Agreement (DPA) available upon request
- Data processed in accordance with GDPR Article 28
- Privacy by design and by default principles applied
7.3 Healthcare Professional Responsibility
As a healthcare professional, you are responsible for:
- Ensuring patient consent for data collection
- Using the App in compliance with local healthcare regulations
- Maintaining confidentiality of patient information
- Following your organization’s data protection policies
8. Your Rights
In accordance with the nFADP (and GDPR where applicable), you have the right to:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data, subject to legal retention obligations
- Objection: Object to processing based on legitimate interests
- Restriction: Request limitation of processing in certain circumstances
- Data Portability: Receive your data in a structured, machine-readable format (where applicable)
- Withdrawal of consent: Withdraw consent at any time, without affecting the lawfulness of prior processing
To exercise these rights, contact us at: support@mycareathome.ch
We will respond within the timeframes required by applicable law.
You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / IFPDT): www.edoeb.admin.ch
9. International Data Transfers
MyCare@HOME is operated from Switzerland and primarily intended for use in Switzerland and the European Economic Area. Data is hosted on Microsoft Azure infrastructure. Where any transfer outside Switzerland or the EEA occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and the mutual adequacy recognition between Switzerland and the EEA.
10. Children’s Privacy
MyCare@HOME is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors without parental or legal guardian consent.
Note: Patient or family member assessment data may include information about minors, collected by healthcare professionals or family members as part of their care duties.
11. Updates to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be communicated via:
- Email notification to registered users
- In-app notification upon next login
- Updated “Last Updated” date at the top of this document
Continued use of the App after changes constitutes acceptance of the updated policy.
12. Data Breach Notification
In the event of a data breach that may affect your personal data:
- We will notify affected users as required by nFADP (without undue delay)
- Notification will include: nature of the breach, data affected, steps taken, and recommendations
- We will notify the FDPIC as required by law
13. Contact
For any questions regarding this Privacy Policy or the processing of your personal data:
Giulia Indemini Email: support@mycareathome.ch Address: In Campii 36, 6673 Maggia, Switzerland
14. Legal Information
Data Controller: Giulia Indemini — In Campii 36, 6673 Maggia, Switzerland — support@mycareathome.ch
Applicable Laws:
- Swiss Federal Act on Data Protection (nFADP / LPD), revised version in force since 1 September 2023
- General Data Protection Regulation (GDPR – EU 2016/679), applied by design
- Applicable cantonal and federal healthcare regulations in Switzerland
Governing Jurisdiction: Courts of the Canton of Ticino, Switzerland
15. Definitions
- Personal Data: Any information relating to an identified or identifiable individual
- Processing: Any operation performed on personal data (collection, storage, use, disclosure)
- Data Controller: The entity that determines the purposes and means of processing
- Data Processor: The entity that processes data on behalf of the controller
- Data Subject: The individual to whom personal data relates
- nFADP: Swiss Federal Act on Data Protection (revised), in force since 1 September 2023
- GDPR: General Data Protection Regulation (EU 2016/679)
Version: 1.0 © 2026 Giulia Indemini. All rights reserved.
