1. Data controller
MediBalans Christina Biri AB, company registration number 559249-7290, is the controller for the processing described in this policy.
Visiting address: Banérgatan 10, first floor, 115 23 Stockholm, Sweden.
Email: [email protected]
Telephone: +46 76 686 76 67
2. Personal data we process
Website and contact
Technical information such as IP address and server logs, together with the contact details and message that you choose to send us.
Booking
Name, a Swedish personal identity or coordination number when you have one, otherwise date of birth, together with email, telephone number, selected service, practitioner and time. The booking flow must not be used to provide symptoms or other health details.
Laboratory-test purchases
Contact and delivery details, the test ordered, payment status, order details and necessary communication about the sample kit. A test purchase may itself reveal health-related information.
Care, samples and results
Patient records, medical history, prescriptions, laboratory orders, sample identifiers, results and other information required for safe care and follow-up.
Do not send a personal identity/coordination number, date of birth, test results or a detailed medical history through the public chat or ordinary email. The chat is not an emergency service. For urgent symptoms, contact 112 or 1177 as appropriate.
3. Purposes and legal bases
- To respond to an enquiry and manage a booking, contract, order, delivery and payment.
- To meet legal obligations, including accounting, patient safety and medical-record requirements.
- To provide healthcare, medical assessment, laboratory handling and follow-up where the processing is necessary for care.
- To protect our systems, prevent misuse and document technical errors.
Health data is sensitive personal data. When it is processed in healthcare, the processing is carried out under the rules that apply to healthcare providers, including the Swedish Patient Data Act and the GDPR exception for necessary care under the responsibility of professionals subject to confidentiality. Read more from the Swedish Authority for Privacy Protection (IMY).
4. Who may receive the data?
We restrict access to the people and service providers that need the data for their assignment. Depending on the service you use, recipients may include:
- booking and patient-record systems, and healthcare professionals involved in your care,
- Meet Mario for the website's booking and chat functions,
- Stripe and relevant payment providers to process and document payment,
- a carrier used to deliver or return a sample kit,
- Genova Diagnostics or another named laboratory for sample handling and laboratory analysis,
- IT, hosting, email and security providers, and public authorities where required by law.
Some laboratories or technical providers may be located outside the EU/EEA. Where a service involves such a transfer, it must be limited to what is necessary and covered by an applicable transfer mechanism and safeguards. For a laboratory test, the laboratory and sample destination are stated in the test or order information.
We do not disclose test names, purchase details or customer identifiers to Meta or other advertising platforms for conversion tracking.
5. How long we retain data
We retain data for as long as it is needed for the purpose for which it was collected, and afterwards where required by law, patient safety or legal claims.
- As a general rule, patient records must be retained for at least ten years after the most recent entry. Read more from 1177.
- Accounting and transaction records are retained for the period required by accounting legislation.
- Ordinary contact and booking data is deleted or anonymised when it is no longer needed, unless it has become part of a patient record or other legally required documentation.
- Technical security logs are retained for a limited period based on security needs.
7. Your rights
Depending on the processing and its legal basis, you may request access, rectification, restriction, erasure or data portability, or object to certain processing. The right to erasure is not absolute; patient records and accounting data may need to be retained by law.
We may need to verify your identity before disclosing or changing data. Read more about your rights from IMY.
8. Contact, questions and complaints
Contact [email protected] if you wish to exercise a right or have questions about how we process your data. Do not include sensitive health information in your first email; we will direct you to an appropriate channel.
If you believe personal data is being processed incorrectly, you may lodge a complaint with the Swedish Authority for Privacy Protection.
We update this policy when our services, providers or legal requirements change. The latest version is always published at this address.