Privacy Policy
1. Preamble
Thyrotracks places the utmost importance on protecting your personal data and ensuring compliance with Regulation (EU) 2016/679 – the General Data Protection Regulation ("GDPR").
This Privacy Policy is intended to provide you with clear and transparent information regarding:
- The personal data we collect;
- The purposes for which we collect such data and the legal basis for doing so;
- How your data is processed, secured, and retained;
- Your rights and how to exercise them;
- Who may access your data;
- Our use of cookies.
2. Principles of Data Processing
In accordance with the GDPR, all data processing operations carried out by Thyrotracks comply with the following principles:
- Lawfulness, fairness, and transparency: Data is processed lawfully, fairly, and transparently.
- Purpose limitation: Data is collected for specific, explicit, and legitimate purposes.
- Data minimization: Only data that is strictly necessary is collected.
- Accuracy: Inaccurate data is updated or corrected.
- Storage limitation: Data is retained only for as long as necessary for the stated purposes.
- Security: Appropriate technical and organizational measures are implemented to ensure the confidentiality, integrity, and availability of your data.
3. Data Collected and Purposes
3.1 – Types of Data Collected
As part of using our services (mobile application, web application, website), we collect the following categories of data:
Identification Data
- First and last name, gender, date of birth
- Email address, phone number, mailing address
- Login credentials
Browsing Data
- IP address, date/time of connection, device type, operating system, navigation logs
Location Data
When certain features are enabled (e.g., appointment reminders), approximate location data may be used but is never stored.
3.2 – Purposes of Data Processing
The data collected is used to:
- Create, manage, and secure your user account
- Enable personalized health monitoring based on recommended care protocols
- Facilitate communication and collaboration between you and your physician
- Manage your health agenda (reminders, lab tests, ultrasounds, etc.)
3.3 – Legal Basis for Processing
- Consent: For processing health-related data, newsletters, or participation in research
- Contractual necessity: For providing access to the platform, creating user accounts, and delivering personalized services
- Legal obligations: For securely storing health data (HDS-compliant hosting)
- Legitimate interest: For continuous improvement of the service and user support
4. Data Controller
The data controller is:
Thyrotracks, a simplified joint-stock company (SAS) with a share capital of €1,000, registered with the Paris Trade and Companies Register under registration number (pending).
Represented by its President (to be confirmed).
For all inquiries: contact@thyrotracks.com
5. User Rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- Right of access: Obtain a copy of your personal data
- Right to rectification: Correct inaccurate or outdated data
- Right to erasure: Request the deletion of your data (subject to legal retention obligations)
- Right to data portability: Receive your data in a structured, commonly used, machine-readable format
- Right to restriction or objection: Restrict or object to certain processing operations under specific conditions
- Right to withdraw consent: At any time, for processing based on consent
- Right to define post-mortem directives: Regarding the handling of your data after your death
- Right to lodge a complaint: With the French Data Protection Authority (CNIL) – www.cnil.fr
To exercise your rights: contact@thyrotracks.com
Proof of identity may be required.
6. Data Hosting
Your health data is hosted in France by a certified Health Data Hosting (HDS) provider: OVH Groupe, 2 rue Kellermann, 59100 Roubaix, France.
7. Cookies
When browsing our website (thyrotracks.com), cookies may be stored on your device. These include:
- Strictly necessary cookies: For proper functioning of the website
- Analytics cookies: For anonymous traffic measurement (e.g., Google Analytics or equivalent)
- Customization cookies: Activated only with your consent
You can manage your cookie preferences at any time via the consent banner or your browser settings.
8. Policy Updates
Thyrotracks reserves the right to update this Privacy Policy at any time to reflect legal, technical, or functional changes.
Last updated: June 25, 2025
We encourage you to review this page regularly. In the event of significant changes, we will notify you by email or through the platform.