Welcome to the Privacy Policy for the Selfnest website and app owned by the company Selfnest platforma d.o.o. Novi Sad (we, us, our, Selfnest).
This Privacy Policy applies to all personal data collected through our website and app Selfnest, that is collected and processed by Selfnest platforma d.o.o., a Serbian company with its registered seat at Augusta Cesarca 18, 21000 Novi Sad.
Selfnest as a data controller collects and processes personal data relating to interactions on the Website and App and the use of the tools and features of the Selfnest website and app (as defined in Section 2).
Your privacy is very important to us. We are devoted to safeguarding our client’s private information and ensuring the highest level of confidentiality and protection of your personal data. This Privacy Policy describes the type of information we collect, what is the purpose of collection and process of your personal data, how we store them, and what rights you have in relation to it. It is intended to inform you of our policies, procedures, and practices regarding collection, processing and disclosure of any information through our Website and App. Therefore, we strongly urge you to read this Privacy Policy very carefully and make sure that you fully understand and agree with it. If there are any terms in this Privacy Policy you do not agree with, please discontinue using our Website and App and our Services.
We believe in full transparency, which is why we keep our Privacy Policy simple and easy to understand. However, if you have any concerns, please contact us at support@selfnest.com.
The following terminology applies to these Use of Terms:
App, Selfnest, Platform refers to our website, web and mobile application Selfnest;
Client, Patient, User, You, Your or Data Subject refers to any natural person that shares personal data with us through the Website and App;
Cookies refer to small pieces of data stored on your device (computer, mobile, or any other device). This information is used to track your use of the Selfnest Website and App, and to compile statistical reports on website activity. For further information about the use of cookies and how you can manage them,please read our Cookie Policy, available at https://www.selfnest.com/en/cookies_policy
Consent refers to your explicit, freely given, informed and unambiguous consent on the processing of personal data. Persons who are 15 years of age or older may give free consent to the processing of their personal data.
Controller or Data Controller refers to the Selfnest platforma d.o.o Novi Sad, that determines the purposes and means of the processing of personal data through the use of the Website and App and online therapy services;
Data concerning health refers to personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;
EEA refers to the European Economic Area;
EU refers to the European Union;
GDPR refers to the EU General Data Protection Regulation available at https://eur-lex.europa.eu/eli/reg/2016/679/oj;
Personal Data Protection Act or PDPA refers to the Act on Personal Data Protection of the Republic of Serbia (“Official Gazette of Republic of Serbia” no. 87/2018);
Privacy Policy refers to this Privacy Policy;
We, Us, or Our refers to Selfnest platforma d.o.o Novi Sad, and any of its affiliates;
Personal Data, Personal Information or Data refers to information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, either directly or indirectly (such as name, identification number, location data, URL address, or any other identifier to physical, physiological, genetic, mental, economic, cultural or social identity of that natural person). Therefore, data about a company or any legal entity is not considered to be personal data but registering on behalf of a legal entity may include sharing personal data. For example, the information in relation to one-person companies may constitute personal data where it allows the identification of a natural person. The rules also apply to all personal data relating to natural persons in the course of professional activity, such as the employees of a company or organization, business e-mail addresses like firstname.surname@company.com;
Platform refers to our Selfnest platform for provision of online therapy services by the licensed therapist to the clients;
Processor, Data Processors refers to any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various service providers in order to process your data more effectively.
Processing or Data processing refers to any operation or set of operations which is performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Service refers to online therapy services provided through our platform/website and app;
Supervisory authority refers to an independent public authority that is authorized for the protection of your personal data in your country;
Therapist refers to a licensed therapist that provides online therapy services to the Client(s) through our Selfnest Website and App;
Third party refers to a natural or legal person, other than you and us, who is authorized to process personal data;
Website refers to our online therapy website Selfnest;
USA refers to the United States of America.
Any use of the above terminology or other words in the singular, plural, capitalization and/or he/she or they, are taken as interchangeable and therefore as referring to the same.
The Selfnest Website and App (Platform) are designed and owned by Selfnest platforma d.o.o. Novi Sad. We are a Serbian company, with office seat at Augusta Cesarca 18, 21000 Novi Sad, registration number: 21718726. As a controller, we determine the purposes and means of the processing of your personal data and we are responsible for your personal data’s confidentiality and safety.
Since we take your privacy very seriously, our employees, contractors, consultants, interns and therapists are contractually bounded and obliged to comply and be governed by this policy.
This Privacy Policy also applies to:
To let us operate the Platform effectively and to let you use the Platform, including the Online Therapy Services, we may have to collect your personal data:
In certain cases, the information you share with us is the data concerning health and is related to your physical or mental health. We may collect and process that information only if you give us your consent to do so. You may decide which Information if any, you would like to share with us, but some functions of the Platform may not be available to you without providing us the necessary Information. By deciding to provide the Information you agree to our methods of collection and use, as well to other terms and provisions of this Privacy Policy.
We collect your personal data that you provide to us voluntarily when you contact us through Contact Form or by sending us an inquiry at support@selfnest.com or through our contact form, we may receive your name and surname, e-mail address, the content of the messages or attachments you may send to us and any other personal data you voluntarily choose to provide us.
Please bear in mind that, we may ask you to provide us with additional information (such as phone number, etc.) so we could process your inquiry. Also, if the content of your inquiry is related to engaging us, we may ask you to provide any other personal information necessary for us to provide our Services.
We may collect your personal data that you provide us when expressing interest in using online therapy services through our Platform. In such case, you will need to fill in the questionary that requires you to give us some of your personal data. Also, in order to provide you the best experience and to meet your needs in the best way, you might be asked to provide us with some of your data concerning health and mental health, illness history. We will collect these data only with your consent that you might revoke at any time. Please note that, should you refuse to give us some of your data concerning your health, it might affect the quality of our assessment of your need and later on online therapy services.
If you decide to create an account at our Platform, we collect, process, and use your information:
By using the online therapy services through our Platform, you might be required to share some personal data information with your Therapist. This may include your personal information, such as name, surname, gender, age, etc. (please note that you are also able to use the services anonymously), your contact person in cases of emergency or mental health crisis. In certain cases, you may be required to share your physical or mental health, illness history data with your Therapist. You may decide not to share such information, but be aware that then the Therapist would not be able to provide you with the best sort of therapy.
Also, you may share your personal data with the Therapist during the sessions, where you voluntarily decide to share such information with the Therapist.
On our Platform, you also can use our chat rooms. In some discussions, you may share your personal data with other users in a common chat. The information you share in common chat is provided by you exclusively upon your voluntarily intentionally given consent.
Since this chat room is created to help people get into contact, share their experiences and stories, it is essential that you respect others’ privacy. Therefore, it is forbidden to post content or take any action on the Platform that infringes or violates someone else's rights or otherwise violates the law. We are entitled to remove and delete any content or information you post on the Platform that we consider as problematic and vulnerable. Also, you are obliged to respect other’s intellectual property rights, not share any financial information (especially billing information) in the common chat rooms nor any ID document or document with sensitive content (such as diagnosis, etc.).
We use cookies, which are small data files transferred to your computer’s hard disk for record-keeping purposes. We are using them in order to enable the technical operation of the Platform, to improve its functionalities and performances, and to administer logging into your account at the Platform, and to collect the Log Data. By using the cookies, you agreed with, we may collect some of your personal data. Please read our Cookies Policy to see how we use them. You can control the usage of cookies at any time by changing your browser’s settings (please see instructions in our Cookies Policy). However, please keep in mind that if you do not accept certain cookies, like strictly necessary ones, you may not be able to use the Platform properly. Our Platform may also use certain third-party cookies for the purposes of web analytics, targeting, marketing, etc. Those third-party cookies are not covered by our Privacy & Cookies Policies and we cannot control their compliance with data privacy, so you will need to visit their official Cookie Policy in order to get familiar with their policy.
We collect and share data about Therapists who offer services on our platform, such as professional experience, expertise, biographical information, sex, name and surname, and profile photo.
Technical Data. The information we collect automatically may include information like your IP address, device type, unique device identification number, browser type, broad geographic location (e.g. country or city-level location) and other technical information. We automatically collect that information when you visit, use or navigate our Website. This information does not reveal your specific identity (like your name or contact information) and is primarily needed to maintain the security and operation of our Website, and for our internal analytics and reporting purposes.
Your Usage Data. We collect and record data and sessions about how you are accessing and using our web application. Such information may include personal data
Mobile Device Access. We may request access or permission to some of the features from your mobile device (such as a microphone, calendar, camera, contacts, reminders, SMS messages, storage, etc.). If you wish to change our access or permissions, you may do so in your mobile device’s settings.
We may allow service providers to access information so they can help us provide services. IP addresses are used to identify the location of users, the number of visits from different countries and also to block disruptive use; and analyze and improve the services offered on our website, e.g. to provide you with the most user-friendly navigation experience.
It is necessary for us to collect and process your personal data:
We collect and process personal data named in point 4 for the following purposes and based on the following legal basis:
Purpose | Legal Basis |
---|---|
If you show the interest in our services by filling in the questionary and/or creating an account. | Your consent - unless providing personal data is necessary to provide a Service or part thereof, the provision of your personal data is not a statutory or a contractual requirement and you may refuse to disclose any data. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. |
To provide you with the best-quality service and individually adapted online therapy. | It is our legitimate interest or a third-party legitimate interest to use personal data in such a way to ensure the best quality of the services provided through our Platform. |
To process inquiries and request you sent us via the contact form or by mailing at support@selfnest.com to respond and improve our services to you. | Processing is necessary for the performance of the Agreement on provision of services or to enter into agreements with you. |
If you send us an inquiry, we will collect data you decide to share with us. | Your consent - unless providing personal data is necessary to provide a Service or part thereof, the provision of your personal data is not a statutory or a contractual requirement and you may refuse to disclose any data. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. |
By using cookies we collect some of your personal data to help us measure traffic and usage trends for the Service, to enable proper functionalities of features and tools at the Website, and to improve our Services. | Processing is based on your consent you explicitly gave by accepting our Cookies Policy and allowing the usage of cookies. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. You may block or opt-out any of the cookies used, in accordance with our Cookies Policy. |
Provision of the services through our Platform to existing and new clients. | Processing is necessary for the performance of contractual obligations we have towards you. |
We will never:
We are the only processor of your data. We do not engage any natural or legal person to process your data on our behalf and for our account.
We take administrative, technical, organizational and other measures to ensure the appropriate level of security of personal data we process. Upon assessing whether a measure is adequate and which level of security is appropriate, we evaluate the nature of personal data we are processing and the nature of the processing operations we perform, the risks to which you are exposed to by our processing activities, the costs of the implementation of security measures and other relevant matters in the particular circumstances.
However, since we are using the Internet-based service carriers, we cannot guarantee 100% security of your personal data. However, we applied industry standards and best practices to prevent any unauthorized access, use, and disclosure. Some of the measures we have taken are encryption technology, anonymization, data backup strategy, firewall, etc.
Also, our employees possess appropriate knowledge and understanding of the importance and confidentiality of your personal data security. Furthermore, we have restricted access to information about you to those employees authorized to access that information within their job description and responsibilities. We take appropriate disciplinary measures to enforce employee privacy responsibilities. All of our employees who have access to your data are bounded by the confidentiality clauses.
Also, the therapists that provide you with online therapy services are educated on the importance of confidentiality and client’s personal data security. Except by being bound with doctor-patient privilege, they are bounded by the non-disclosure agreement concluded with us.
We have entered into non-disclosure agreements with them.
Phishing
Online identity theft and account hacking, including phishing, is of great concern. We took appropriate technical measures to verify all of your billing information before billing as well as to protect your billing information from any fraud and illegal use. However, you should always be diligent when you are being asked for your account information and you must always make sure you do that in our secure system. We will never request your login information or your credit card information in any non-secure or unsolicited communication (email, phone, or otherwise).
We will not share your personal data with third parties, unless:
In certain cases, we are required to cooperate with authorities, governmental bodies, and officials in order to comply with the law. We may disclose the information if necessary to protect the safety of the public or any person, to respond to claims and legal process, activities that may be illegal or dangerous. Please note that the Therapist might also be obliged to share your information with authorities, especially in case of some mental illnesses that lead to (a) reported or suspected abuse of a child or vulnerable adult; (b) serious suicidal potential; (c) threatened harm to another person; (d) court-ordered presentation of treatment.
We utilize external processors for certain processing activities. We use information audits to identify, categorize and record all personal data that is processed outside the company, so that the information, processing activity, processor and legal basis are all recorded, reviewed, and easily accessible.
We have strict due diligence procedures and measures in place and review, assess and background check all processors prior to forming a business relationship with them. We obtain company documents, certifications, references and ensure that the processor are adequate, appropriate and effective for the task we are employing them for.
We audit their processes and activities prior to forming a business relationship and during the relationship period to ensure compliance with the data protection regulations and review any codes of conduct that oblige them to confirm compliance.
We may share your information with third parties for business purposes, e.g.:
This is the list of processors with whom we share your personal data:
Processor | Role | Seat |
---|---|---|
Google, Inc. | Analytics | USA |
Facebook, Inc. | Social media account | USA |
Instagram, Inc. | Social media account | USA |
LinkedIn, Inc. | Social media account | USA |
We collect your personal data in the Republic of Serbia. We may transfer your data only to the following countries:
On our Platform we may share the links to other websites, services or offers which are owned, operated or maintained by third parties. If you click on such a link, you will be directed to that third website or service. Please be aware that we do not have control over their websites and services and we do not have control over their privacy policies and terms of use.
We keep your information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless otherwise required or permitted by law.
The period for which we store your personal data depends on a particular purpose for the processing of personal data within the use of our Website.
In determining data retention periods, we take into consideration local laws, contractual obligations, and the expectations and requirements of our customers and suppliers. We securely delete or destroy your personal information when we no longer need, or when you request us to delete your personal information.
Please note that under Serbian law, the right to be forgotten when you request deletion ofyour data once you cease using our Platform may not be fullyexercised when it comes to the health concerning data. Namely, weare obliged to keep certain health concerning data up to ten yearsor even permanently. Therefore, we cannot erase private health datadirectly upon your request, as it may be considered essential forother medical file retention purposes. Applicable individual countrymedical retention laws are generally considered an acceptableexception to the regulations regarding the right to deletion ofcertain data.
You can send us a request for a copy of personal data we hold about you.
We have ensured that appropriate measures have been taken to provide such processing in a concise, transparent, intelligible and easily accessible form, using clear and plain language. Such information is provided in writing and free of charge. It may be provided by other means when authorized by you and with prior verification as to the subject’s identity.
We will provide you with information about what type of personal data we collect, the purpose of collecting and processing, how we store them and for how long, with whom we share it, as well as about your right to complain to the supervisory authority.
Information is provided to you at the earliest convenience, but at a maximum of 30 days from the date we received your request. Where the retrieval or provision of information is particularly complex or is subject to a valid delay, the period may be extended by two further months where necessary.
If personal data we have about you is incorrect, you have the right to request that we correct those data. When you notify us about the inaccurate data, we will rectify the error within 30 days and inform any third party of the rectification if we have disclosed personal data in question to them.
You have the right to request that we delete your personal data in certain cases including:
However, this right does not apply when processing is necessary, for example:
(Please see the exception for medical records in point 12 of this Privacy Policy)
If the accuracy of personal data is contested, you consider the processing is unlawful but you do not want it erased, we no longer need personal data but you require it for the establishment, exercise or defense of legal claims or you have objected to the processing and verification, you can exercise your right to the restriction of processing.
We will communicate that we have done any rectification or erasure of personal data or restriction of processing to all recipients to whom we have disclosed your personal data, unless this proves impossible or involves disproportionate effort.
We will also notify you about those recipients if you request that.
If you have provided your consent to the collection, processing and transfer of your personal data, you have the right to fully or partly withdraw your consent. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented, unless there is another legal ground for the processing and unless otherwise we are obliged by the applicable law.
If you have any concerns or requests in relation to your personal data and its protection, please contact us at support@selfnest.com and we will respond within 30 days.
If you are unsatisfied with how we process your data, you may contact the competent supervisory authority.
In case you believe that we are processing your personal data contrary to the applicable law, you have the right to lodge a complaint with the supervisory authority located where you reside or work or where the alleged infringement took place.
By using the cookies you agreed with, we are allowed to collect some of your personal data. Processing is based on your consent you explicitly gave by accepting our Cookies Policy and allowing the usage of cookies. You have the right to withdraw your consent at any time, without affecting the lawfulness of the processing based on consent prior to such withdrawal. You may block or opt-out any of the cookies used, in accordance with our Cookies Policy. If you choose to remove or reject cookies, this could affect certain features, tools or services of our Website.
We do not collect and process any information from persons under the age of 16 without prior express written consent of the parents. If you are under the age of 16, please stop using the Platform or make sure that your parents are present and have consented.
If you are aware that we have unknowingly collected personal data from a child under the age of 16, please let us know by contacting us and we will delete such information.
We reserve the right to change our Privacy Policy from time to time at our sole discretion. If we make any changes, we will publish the new Privacy Policy on our Website.
If you have previously consented to our Privacy Policy, your continued use of the Website after the changes we have made shall be deemed as your acceptance of the updated rules.
If you have any questions, concerns and/or objection about our Privacy Policy and/or privacy-related practices and your rights related to personal data protection, please get in touch with our Data Protection Officer at support@selfnest.com., or by writing to:
Selfnest platforma doo
Data Protection Officer
Augusta Cesarca 18
21000 Novi Sad, Serbia
Citizens of EU/EEA: If you live within the European Union or EEA and have any questions, concerns and/or objection about our Privacy Policy and/or privacy related practices and your rights related to personal data protection, you may contact our EU representative at support@selfnest.com.