Privacy policy

This Privacy Policy (updated as of September 2023) describes how BERDAC collects, processes, uses, and discloses your information, including your personal data and web access data (www.ima.health or other derivatives).
Please read this Privacy Policy carefully, as by using our service, you accept this document as well as the Terms and Conditions related to it.
Any reference in this document to "we," "our," or "us" refers to the Website (hereinafter referred to as the "Data Controller").
The Data Controller is BERDAC SMART SERVICES S.L. (hereinafter BERDAC).
This Privacy Policy also concerns Payment Services in accordance with the provisions of the Service Payment Terms (hereinafter the "Payment Terms"). When you use Payment Services, you will also be providing your data, including personal data, to the website, which will also act as the Data Controller (hereinafter the "Payment Data Controller") for your information related to Payment Services.
This Privacy Policy applies to all Users of the Service, including all visitors, browsers, providers, advertisers, and/or content contributors ("Users"). If you do not agree with any part of this Privacy Policy, you should not use the Service.
Your continued use of the Service will constitute acceptance of this Privacy Policy as well as the Terms and Conditions. Any new feature or tool added to the current Service will also be subject to the same. BERDAC reserves the right to update, change, or replace any part of this Privacy Policy and Terms and Conditions by posting updates and/or changes.
It is your responsibility to periodically review the Service for changes. Your continued use of the Service after the posting of any changes constitutes acceptance of such changes.
Please see Section 8 for contact information of the Data Controllers and detailed Payment Data Controllers.
Information BERDAC Collects
Information is collected belonging to three general categories:

Data You Provide to BERDAC
Information Collected: To use the Website and/or any other environment or tool
BERDAC requests and collects personal data about you when you use the Website.
This data is necessary to fulfill BERDAC's legal obligations. Without this data, BERDAC may not be able to provide all requested services.

The requested and collected data are as follows:
Account Information
When registering for an Account, certain information such as your name, surname, email address, address, username, image, and the password you select is required. This information can be edited at any time from your Account.
Voluntarily Provided Information
You may provide additional personal data to BERDAC to have a better user experience when using the Website and/or any other environment or tool. This additional information will be processed with your consent.
For the use of the Service, the content you provide through BERDAC's environments is collected, for example: photographs, medications (including dosage and timing), medical history, etc. Such user content may include personal information.
Other Information
You may choose to provide information by filling out any form, conducting a search, updating or adding information to your Account, responding to surveys, posting on community forums, participating in promotions, or using other features of the Website.

Information Necessary for the Use of Payment Services
The Payment Data Controller needs to collect other data, as they are necessary for the proper execution of the contract formalized with you and for compliance with applicable legislation (such as anti-money laundering regulations). Without this data, you will not be able to use Payment Services. This data includes:
Payment Information
When using Payment Services, the Payment Data Controller will require certain financial data (such as your bank account or credit card details) to process payments and comply with applicable legislation.
Identity Verification and Other Data
The Payment Data Controller may require information to verify your identity (such as photographs of your government-issued identification document, passport, national ID card, or driver's license) or other authentication data, your date of birth, address, email address, phone number, and other data to verify your identity, provide Payment Services, and comply with applicable legislation.

Information Automatically Collected by BERDAC from Your Use of the Website
When you use the Website, Payment Services, and/or any other environment or tool, BERDAC automatically collects information, including your personal data, about the services you use and how you use them. This information is necessary for the proper execution of the contract formalized between you and BERDAC, for compliance with BERDAC's legal obligations, and considering the legitimate interest in providing and improving the functions of the Website, Payment Services, and/or any other environment or tool.
Registration Data and Device Information
BERDAC automatically gathers registration information and information about your Device each time you access the Website or any other environment or tool. This information includes, among other data, details about how you have used the Website (including if you have clicked on links to third-party applications), IP address, access dates and times, hardware and software information, Device information, Device event information, unique identifiers, data about locks, cookie data, and the pages you have viewed or interacted with before or after using the Website.
Cookies and Similar Technologies
BERDAC uses cookies and other similar technologies, such as web beacons, pixels, and mobile identifiers.
Additionally, BERDAC may allow its business partners to use these tracking technologies on the Website or may engage others to track your behavior on its behalf, although you can disable the use of cookies through your browser settings.
Transactional Information
The Website collects information about your payment transactions made, including the payment instrument used, date and time, payment amount, billing zip code, email address, your address, and other transactional data. This data is necessary for the proper execution of the contract formalized between you and BERDAC and for the provision of Payment Services.

Information BERDAC Collects from Third Parties
The Website may collect information, including personal data, that others provide about you each time they use the Website, Payment Services, and/or any other environment or tool, or obtain information from other sources and combine it with what BERDAC collects.
BERDAC does not control, monitor, or take responsibility for how third parties who provide your information process your personal data, and any requests for information regarding the disclosure of your personal data made to BERDAC should be directed to such third parties.
To the extent permitted by applicable law, BERDAC may receive additional information about you, such as demographic data or fraud detection data, from third-party service providers or partners and combine it with the information BERDAC has about you.

How BERDAC Collects Information
BERDAC uses, stores, and processes information about you, including your personal data, to provide services, understand, improve, and develop the website and to create and maintain a trusted and secure environment and to comply with BERDAC's legal obligations. Specifically, the purposes are:
Providing Services
To provide services through the website and/or any other environment or tool.
Perform any function BERDAC believes in good faith is necessary to protect the security or proper functioning of the service.
Track user activity to better understand preferences.
Respond to inquiries and provide support and assistance to services.
Resolve user disputes and requests.
Enforce the General Conditions and Terms and Conditions.
Providing, Improving, and Developing the Website and/or any other environment or tool
Enable you to access the Website and/or any other environment or tool for use.
Direct, protect, improve, and optimize the Website, any environment or tool, as well as the experience, for example, through analysis and research efforts.
Provide customer service.
Send you messages about the service or support, such as updates, security alerts, and account notifications.
If you provide BERDAC with your contact information, the company may process it:
to facilitate your invitations by recommendation;
to send your reference requests;
to carry out detection and prevention of fraudulent activities;
and for any purpose you authorize at the time of collection.
To direct, protect, improve, and optimize the Website, any environment or tool, and to personalize your experience, your interactions, searches, history, profile information, preferences, and other content you submit to them are analyzed.
BERDAC processes this information considering the legitimate interest in improving the Website and/or any other environment or tool, as well as the experience within it.

Create and Maintain a Trusted and Secure Environment
Detect and prevent fraudulent activities, spam, insults, security incidents, and other harmful acts.
Conduct security investigations and risk assessments.
Verify or authenticate information or identifications you have provided.
Conduct checks with databases and other sources of information, to the extent permitted by applicable legislation and subject to your consent, where applicable.
Comply with BERDAC's legal obligations.
Enforce the General Conditions and Terms and Conditions.
In relation to the aforementioned activities, BERDAC may analyze interactions you have with the website and/or any other environment or tool, your profile information, and any other content you submit, as well as information obtained from third parties. In certain cases, automated processes may restrict or suspend your access to the Website and/or any other environment or tool if such processes detect activity that may pose a security risk.
BERDAC processes this information considering the legitimate interest in protecting the Website and/or any other environment or tool, to assess the proper execution of the contract formalized with you, and to comply with applicable legislation.

Provide, Personalize, Measure, and Improve BERDAC's Advertising and Marketing
Send you promotional messages, marketing content, advertisements, and other information that may interest you based on your preferences, as well as advertising through social communication platforms such as Facebook or Google.
Personalize, measure, and improve BERDAC's advertising.
Manage referral programs, rewards, surveys, sweepstakes, contests, or other promotional activities or events sponsored or managed by the website or by Third-Party Partners of BERDAC.
Profile your characteristics and preferences (based on the information you provide, your interactions with the Website and/or any other environment or tool, information obtained from third parties, and your search history) to send you promotional marketing or advertising messages, as well as other information that BERDAC considers may be of interest to you.
BERDAC will process your personal information for the purposes outlined in this section considering our legitimate interest in conducting marketing activities to offer products or services that may be of interest to you. You can opt-out of these marketing communications by following the instructions provided in BERDAC's marketing communications or by changing notification settings in your Account.

How the Payment Data Controller Uses the Collected Information
To enable you to access and use Payment Services.
To detect and prevent fraud, abuse, security incidents, and other harmful activities.
To conduct security investigations and risk assessments.
To perform database checks and other sources of information.
To comply with legal obligations (such as anti-money laundering regulations).
To enforce Payment Terms and other payment policies.
All of this is used with your consent, to send you promotional marketing messages, advertisements, and other information that may be of interest to you based on your preferences.
The Payment Data Controller processes this information considering their legitimate interest in improving Payment Services and the user experience with them, and as necessary, for the proper execution of the contract formalized with you, as well as to comply with applicable legislation.

Sharing Information
With Your Consent
When you have given your consent, BERDAC may share your information, including your personal data, as it appears at the time you have consented, with authorized entities:
Hospitals.
Caregivers.
Family members.
Pharmacies.
Insurance companies.
Home Assistance Services.
Residences.
When you authorize a third-party application or website to access your Account or participate in promotional activities carried out by partners or third parties, BERDAC may share your information, including your personal data. Additionally, your personal data is shared when necessary with third-party providers and service providers to enhance treatments and their effectiveness:
Payment platform.
Anonymously to analytics and survey providers (demographic information).
Marketing companies.
Pharmaceutical companies (for example, in cases of poor medication adherence or combination of multiple medications).
In an anonymized (non-identifiable) manner to partners for maintenance, hosting, payment gateways, data storage, security, analytics, and ads.
Information is also shared with third parties when you give consent to BERDAC to do so.

Regulatory Compliance, Response to Legal Requirements, Damage Prevention, and Protection of BERDAC's Rights
The Website and/or any other environment or tool may disclose your information, including your personal data, to courts, law enforcement agencies, or government agencies, or authorized third parties, if BERDAC is obligated or authorized to do so by law, or if such disclosure is reasonably necessary:
to comply with BERDAC's legal obligations;
to comply with legal proceedings and respond to rights claims filed against the Website;
to respond to certified requests related to police investigations or alleged illegal or any other activities that could expose BERDAC, you, or any of BERDAC's users to legal liability;
to enforce the General Conditions, Terms and Conditions, or other contracts with you and regulate them;
to safeguard the rights, property, or personal safety of the Website, its employees, its Members, or members of the public.
When applicable, BERDAC may provide notification to Members about these requests unless:
legal proceedings, court orders received by BERADC, or applicable legislation prohibit such notification;
or BERDAC believes that providing such notification would be futile or ineffective, or would endanger the physical integrity of an individual or a group, or would imply or increase the risk of fraud against property, Members, the Website, and/or any other environment or tool.
In cases where legal requirements are met without notification due to the reasons stated above, BERDAC will attempt to provide notification of the request to said Member after the fact when appropriate, provided it is established in good faith that BERDAC is no longer legally bound by such prohibition.

Social Communication Platforms and Marketing
Where applicable law permits, BERDAC may use certain personal information about you, such as your email address, to use as a hash and share it with social communication platforms such as Facebook or Google, to generate leads, drive traffic to BERDAC's websites, or otherwise promote BERDAC's services, the Website and/or any other environment or tool.
These processing activities are based on BERDAC's legitimate interest in conducting marketing activities to offer products or services that may be of interest to you.
Social communication platforms with which your personal information may be shared are not subject to control or supervision by the website. Therefore, any questions regarding how your social communication service providers handle your personal data should be directed to those providers.
Please note that you can request the Website and/or any other environment or tool to cease processing your data for these direct marketing purposes at any time by sending an email to support@ima.health.

Third-Party Partners and Third-Party Integrations
The Website may contain links to third-party websites or services, such as third-party integrations, joint brand services, or third-party branded services (hereinafter, "Third-Party Partners"). The Website and any other environment or tool do not own or control such Third-Party Partners, and when you interact with them, you may be providing information directly to the Third-Party Partner, to BERDAC, or to both.
Such Third-Party Partners typically have their own policies regarding information collection, use, and disclosure. BERDAC encourages you to review the privacy policies of other websites you visit.

Your Rights
You may exercise the rights set forth in this section with your Data Controller or Payment Data Controller by sending an email to support@ima.health
Please note that BERDAC may ask you to verify your identity before taking any action you have requested.

Management of Your Information
You can access and update some of your data through your Account settings.
You are responsible for keeping your personal information up to date.
Correction of Incorrect or Incomplete Information
You have the right to request BERDAC to correct any incorrect or incomplete personal information about you (that you cannot modify in your Account).

Access to Data and Portability
Applicable law may grant you the right to request copies of the personal data that BERDAC stores about you.
You may also request copies of the personal information you have provided in a structured, commonly used, machine-readable format and/or request BERDAC to transmit such information to another service provider (to the extent technically feasible).

Data Retention and Deletion
In general, BEDAC will retain your personal information for as long as necessary to comply with legal obligations.
If you do not want BERADC to continue using your information to provide the website, you can request your personal information to be deleted, and your Account closed.
Please note that if you request the deletion of your personal information:
- BERDAC may retain some of your personal data to the extent necessary for legitimate business interests, such as detecting and preventing fraud and improving security.
- BERDAC may retain and use your personal information to the extent necessary to comply with legal obligations.
- BERDAC may maintain non-identifiable aggregated data.
- Information you have shared with BERDAC (e.g., forum posts) may continue to be visible to the public on the Web and/or any other environment or tool, even after your Account has been canceled. However, such information will no longer be linked to you.
Additionally, some copies of your information may remain in BERDAC's database, albeit without personally identifying information.
As BERDAC ensures to protect the website from loss or accidental or malicious destruction, your personal information may not be deleted from backup systems for a limited period.

Revocation of Consent and Restriction of Data Processing
In cases where you have authorized the processing of your personal information by the website and/or any other environment or tool, you may revoke your consent at any time by changing your Account settings or by sending a communication specifying the consent you wish to revoke.
Please note that revoking your consent does not affect the legality of data processing based on your consent that occurred before such revocation. Also, in some jurisdictions, applicable law may grant you the right to limit how BERDAC uses your personal information, particularly in cases where:
- You dispute the accuracy of your personal information.
- Data processing is unlawful, and you object to the deletion of your personal information.
- BERDAC no longer needs your personal information for processing, but you request the information for the initiation, exercise, or defense of legal claims.
- You have objected to the processing in accordance with Section 5.6, in which case it will be verified if the Platform has legitimate grounds that prevail over yours.

Objection to Data Processing
Applicable law grants you the right to demand that the website and/or any other environment or tool do not process your personal information for specific purposes (including analyzing your activity for profiling purposes) when such processing is based on legitimate interest.
If you object to such processing, the website and/or any other environment or tool will stop processing your personal data for those purposes unless BERDAC can demonstrate compelling legitimate grounds for the processing or unless such processing is necessary for the initiation, exercise, or defense of legal claims.
If your personal information is processed for direct marketing purposes, you may at any time request the cessation of such data processing for commercial marketing by sending an email to support@ima.health.

Filing Complaints
You have the right to file complaints regarding data processing activities carried out by the Web and/or any other environment or tool with the competent data protection authorities.
You will have the right to lodge a complaint with the relevant supervisory authority.

Security
BERDAC continuously adopts and updates administrative, technical, and physical security measures to improve service security, including the use of SSL certificates, considering that the server where the data is stored is connected to "the cloud" and is owned by Amazon Web Services.
All of this is done to contribute to the protection of your information and prevent its unauthorized destruction, alteration, or unauthorized access.
Firewalls, data encryption, and access controls to information are some of the safeguards that BERDAC uses to protect your information. You should prevent unauthorized access to your account and personal data by selecting and protecting your password properly and by limiting access to your computer and browser by logging out after you have finished accessing your account.
If you know or have reason to believe that your Account credentials have been lost, stolen, misappropriated, or are at risk for any other reason, or if you know or suspect that your Account has been used without authorization, please contact BERDAC following the instructions in section (8) below.

Modifications to this Privacy Policy
BERDAC reserves the right to modify this Privacy Policy at any time pursuant to this provision.
If BERDAC makes changes to this Privacy Policy, the revised version will be published on the Web, updating the "Last Updated" date at the beginning of this document.

Contact
If you have any questions or complaints about this Privacy Policy or about the handling practices of the website and/or any other environment or tool, you can contact BERDAC by email at support@ima.health or at the following address: Av. Meridiana 358, Floor 3, 08027 Barcelona.