Privacy Policy — MyCare@HOME App

Effective Date: 29 September 2026 Last Updated: 29 September 2026


Introduction

Giulia Indemini (“we,” “our,” or “us”) operates the MyCare@HOME mobile application (the “App” or “Service”).

This Privacy Policy describes how we collect, use, disclose, and protect personal data when you use our App. It applies exclusively to the MyCare@HOME mobile application and the data processed through it. The privacy policy for the mycareathome.ch website is published separately.

By using MyCare@HOME, you agree to the collection and use of information in accordance with this policy.


1. Data Controller

The data controller for personal data processed through the App is:

Giulia Indemini In Campii 36 6673 Maggia, Switzerland Email: support@mycareathome.ch

For any questions regarding the processing of your personal data, please contact us at the email address above.


2. Applicable Law

The processing of personal data through this App is governed by:

  • The revised Swiss Federal Act on Data Protection (nFADP / LPD), in force since 1 September 2023, and its implementing Ordinance (OPDa / VDSG);
  • The principles of the General Data Protection Regulation (GDPR – EU 2016/679) are taken into account by design, in anticipation of potential expansion toward the European Union.

3. Information We Collect

3.1 Account Information

When you register and use MyCare@HOME, we collect:

  • Email address
  • Full name
  • Phone number (optional)
  • Professional credentials (for healthcare professional users)
  • Role within your healthcare organization

3.2 Organization Information

  • Organization name and identifier
  • Department or unit affiliation
  • Work location

3.3 Health and Assessment Data

Healthcare professional users (Admin, Manager, Caregiver) may enter:

  • Patient assessment responses (Wellness Check, Clinical Check)
  • Clinical observations and care notes
  • Care recommendations
  • Assessment scores and results
  • Patient names, identifiers, and demographic information
  • Date of birth, gender, health insurance number (AVS), medical history

Free Users (personal use) may enter:

  • Family member names and demographic information
  • Wellness Check assessment responses for family members
  • Assessment results and recommended services

Important: All health data entered by healthcare professionals remains under the control of the respective healthcare organization. MyCare@HOME acts as a data processor on their behalf for that data.

3.4 Usage and Technical Data

We automatically collect:

  • Device information (model, operating system version)
  • App version and build number
  • Features used and interaction patterns
  • Error logs and crash reports
  • Session duration and frequency
  • Language preference
  • IP address and device identifiers
  • Network connection type and app performance metrics

4. How We Use Your Information

We use collected information to:

  • Authenticate users and manage accounts
  • Enable patient and family member assessment workflows
  • Generate clinical and wellness reports (PDF export)
  • Synchronize data across devices via Microsoft Azure
  • Provide role-based access control
  • Analyze usage patterns and improve the App
  • Identify and fix bugs and optimize performance
  • Send important service and security notifications
  • Respond to support inquiries
  • Detect and prevent fraud and unauthorized access
  • Maintain audit logs

4.1 Legal Basis

PurposeLegal Basis
Providing the ServicePerformance of contract
Improving the AppLegitimate interest
Security and fraud preventionLegitimate interest / legal obligation
Health data processingExplicit consent / legal obligation (nFADP Art. 31)
CommunicationsLegitimate interest / consent

5. Data Storage and Security

5.1 Storage

  • Server Storage: All data is hosted on Microsoft Azure infrastructure.
  • Local Storage: Authentication tokens are stored securely using iOS Keychain with encryption.
  • Backups: Regular encrypted backups are maintained.

5.2 Security Measures

  • All data transmitted using HTTPS/TLS encryption
  • Sensitive data encrypted at rest
  • iOS Keychain for secure local storage
  • Database-level encryption
  • JWT (JSON Web Token) based authentication
  • Secure password hashing
  • Automatic session timeout
  • Multi-factor authentication (MFA) enabled for all user roles
  • Role-based access control (RBAC) with principle of least privilege
  • Organization-level data isolation
  • Security audit logging and intrusion detection

5.3 Data Retention

  • Active accounts: Data retained while the account is active
  • Deleted accounts: Personal data deleted within 30 days of account deletion request
  • Health records: May be retained longer to comply with applicable Swiss healthcare regulations
  • Legal requirements: Some data may be retained for the period required by law

6. Data Sharing and Disclosure

6.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6.2 Sharing Within Your Organization

Patient data and assessments are accessible only to authorized users within your healthcare organization, based on role and patient assignments. All access is logged.

6.3 Third-Party Service Providers

ProviderServiceData InvolvedLocation
Microsoft AzureCloud hosting and data storageAll app dataEU / Switzerland
Email service providerNotifications and MFA codesEmail addressTBD

All third-party providers are contractually obligated to process data only as instructed, maintain appropriate security measures, and comply with applicable data protection laws.

6.4 Legal Requirements

We may disclose your information if required to comply with legal obligations (court orders, subpoenas), protect our rights and safety, or investigate fraud or security issues.


7. Healthcare-Specific Considerations

7.1 Swiss Data Protection (nFADP)

  • Health data is treated as sensitive personal data under the revised Federal Act on Data Protection
  • Consent is recorded when a patient or family member is registered
  • Access is governed by role-based authorization
  • Breach notification procedures are in place in accordance with nFADP requirements

7.2 GDPR (European Union)

For EU healthcare organizations:

  • Data Processing Agreement (DPA) available upon request
  • Data processed in accordance with GDPR Article 28
  • Privacy by design and by default principles applied

7.3 Healthcare Professional Responsibility

As a healthcare professional, you are responsible for:

  • Ensuring patient consent for data collection
  • Using the App in compliance with local healthcare regulations
  • Maintaining confidentiality of patient information
  • Following your organization’s data protection policies

8. Your Rights

In accordance with the nFADP (and GDPR where applicable), you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your data, subject to legal retention obligations
  • Objection: Object to processing based on legitimate interests
  • Restriction: Request limitation of processing in certain circumstances
  • Data Portability: Receive your data in a structured, machine-readable format (where applicable)
  • Withdrawal of consent: Withdraw consent at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact us at: support@mycareathome.ch

We will respond within the timeframes required by applicable law.

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / IFPDT): www.edoeb.admin.ch


9. International Data Transfers

MyCare@HOME is operated from Switzerland and primarily intended for use in Switzerland and the European Economic Area. Data is hosted on Microsoft Azure infrastructure. Where any transfer outside Switzerland or the EEA occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and the mutual adequacy recognition between Switzerland and the EEA.


10. Children’s Privacy

MyCare@HOME is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors without parental or legal guardian consent.

Note: Patient or family member assessment data may include information about minors, collected by healthcare professionals or family members as part of their care duties.


11. Updates to This Privacy Policy

We may update this Privacy Policy periodically. Changes will be communicated via:

  • Email notification to registered users
  • In-app notification upon next login
  • Updated “Last Updated” date at the top of this document

Continued use of the App after changes constitutes acceptance of the updated policy.


12. Data Breach Notification

In the event of a data breach that may affect your personal data:

  • We will notify affected users as required by nFADP (without undue delay)
  • Notification will include: nature of the breach, data affected, steps taken, and recommendations
  • We will notify the FDPIC as required by law

13. Contact

For any questions regarding this Privacy Policy or the processing of your personal data:

Giulia Indemini Email: support@mycareathome.ch Address: In Campii 36, 6673 Maggia, Switzerland


14. Legal Information

Data Controller: Giulia Indemini — In Campii 36, 6673 Maggia, Switzerland — support@mycareathome.ch

Applicable Laws:

  • Swiss Federal Act on Data Protection (nFADP / LPD), revised version in force since 1 September 2023
  • General Data Protection Regulation (GDPR – EU 2016/679), applied by design
  • Applicable cantonal and federal healthcare regulations in Switzerland

Governing Jurisdiction: Courts of the Canton of Ticino, Switzerland


15. Definitions

  • Personal Data: Any information relating to an identified or identifiable individual
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure)
  • Data Controller: The entity that determines the purposes and means of processing
  • Data Processor: The entity that processes data on behalf of the controller
  • Data Subject: The individual to whom personal data relates
  • nFADP: Swiss Federal Act on Data Protection (revised), in force since 1 September 2023
  • GDPR: General Data Protection Regulation (EU 2016/679)

Version: 1.0 © 2026 Giulia Indemini. All rights reserved.

Verificato da MonsterInsights