Privacy Policy and Patient Information – Sention Patient Portal
1. About this information
This information describes how Sention Health AB ("Sention", "we", "us") processes your personal data when you are a patient with us and use our patient portal (the "Portal"). Sention is the healthcare provider and the data controller for the processing. This information is provided in accordance with the General Data Protection Regulation (GDPR) and the Swedish Patient Data Act (2008:355, "PDL").
2. What data we process
We process, among other things:
- Identity and contact details: name, personal identity number, email and the information you provide to us.
- Login and technical information: data linked to your BankID login as well as logs of access to and activity in the Portal.
- Health and care data: information about your health, your visits, assessments and other information documented in your patient record or that you provide to us via the Portal.
Health data is sensitive personal data under Article 9 GDPR and is processed with particular care.
3. Why we process the data and legal basis
| Purpose | Legal basis |
|---|---|
| To provide you with care and maintain a patient record | Article 9.2 h GDPR (health and medical care) and the PDL. Record-keeping is a legal obligation (Article 6.1 c). |
| To administer your account and login | Providing the Portal as part of the care we deliver (Article 9.2 h GDPR and the PDL). |
| Security, logging and access control | Legal obligation and legitimate interest (Article 6.1 c and f) as well as the PDL's requirement for access logging. |
| To meet obligations under the law | Legal obligation (Article 6.1 c). |
4. Patient record
As a healthcare provider we are required to maintain a patient record for every patient. The record is kept in order to give you good and safe care, and also serves as a basis for follow-up, quality assurance and supervision. You have the right to access your record. For security reasons we log who has accessed your data, and you can request an extract from that log.
5. How we obtain the data
We obtain data directly from you (in your contact with us), from BankID when you log in, and as a result of the care we provide to you. Where applicable, data may also be obtained from or shared with other healthcare providers in accordance with the law.
6. Who can access the data
Your data is available to the staff at our organisation who need it in order to provide your care and to operate the Portal. In addition, data may be shared with:
- Data processors that operate and maintain the Portal on our behalf (e.g. providers of IT operations, storage and email delivery). These process data only on our instructions and under a data processing agreement.
- Public authorities when we are required by law to disclose data.
We never sell your data.
7. Where the data is processed
Your personal data is processed within the EU/EEA. We do not transfer personal data to countries outside the EU/EEA.
8. How long we keep the data
Data in the patient record is retained for as long as required under the PDL – as a general rule at least ten years after the most recent entry. Other data, such as account administration and logs, is kept for as long as necessary for the purpose and in accordance with applicable legal requirements.
9. Your rights
You have the right to:
- Access the data we process about you, including your record.
- Request rectification of inaccurate data. For record data, rectification is carried out in accordance with the PDL, so that the original entry remains visible.
- Request erasure of certain data. Note that record data may, as a general rule, not be erased on request; the destruction of a patient record is decided by the Health and Social Care Inspectorate (IVO).
- Request a log extract showing who has accessed your data.
- Object to or request restriction of certain processing, within the limits permitted by law.
To exercise your rights, contact us as set out in section 12.
10. Security
We protect your data with technical and organisational measures, including strong authentication (BankID), access control, encryption and access logging, so that only authorised staff can access the data.
11. Complaints
If you believe that we are processing your personal data incorrectly, you can contact us. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), which is the supervisory authority for personal data processing. Complaints concerning the care itself are handled via the Patients' Advisory Committee (Patientnämnden) or IVO.
12. Contact
Sention Health AB, company reg. no. 559425-1000
c/o Medect, Box 24248, 104 51 Stockholm, Sweden
Data protection and privacy enquiries: connect@sention.health
13. Changes
We may update this information. The latest version is always published on our website.