When using the services of Howdy ApS (referred to as “we”, “us” or “ours”) through the Howdy technology platform (“Howdy”), we will process your personal data.
This Privacy Policy (referred to as “Policy”) outlines how your personal data is processed.
We are the data controller responsible for the processing of your personal data as described in the below.
Our contact information:
Howdy ApS
Njalsgade 76,
2300 Copenhagen S
CVR: 35395539
Phone no.: +45 888 777 00
Email: gdpr@howdy.care
Website: www.howdy.care
Overview of processing activities and personal data processed.
To enrol you in Howdy and thereby deliver the services as agreed with your employer. To send you invitations to enrol through the reminder engine.
These are received from your employer. We periodically receive updates from your employer.
(GDPR art. 6 (1)(f)). Our legitimate interest is to provide services to your employer based on our agreement with them. We do this by sending you questionnaires (if you consent) and getting you in touch, if required, with a Response Team and sending wellbeing statistics to your employer and using generic statistics to improve our service.
See chapter 3.
To evaluate your wellbeing and assess whether the Response Team should be activated
Common information:
Special categories of data in the form of health information:
The personal data concerning your answers and wellbeing are received directly from you when you answer the questions in Howdy.
Your explicit consent to process general personal data (GDPR art 6(1)(a)) and special categories of personal data (art 9(2)(a))
We do this by sending you questionnaires and getting you in touch, if required, with a Response Team and sending wellbeing statistics to your employer and generic statistics to improve our service.
See chapter 3.
If your employer has chosen to add the specific module of Howdy in which your employer may define specific feedback questions, your personal data is processed for the purpose of assessing the answers to the questions and provide your employer with statistics.
The personal data are received directly from you when you answer the questions in Howdy.
Your consent to process general personal data (GDPR art 6(1)(a))
See chapter 3.
Some of the modules in Howdy additionally include a proactive Response Team that contacts you with the objective of advising you on how you can seek help, if – based on your answers in Howdy – you are considered to have low wellbeing, are experiencing pain or in any other way qualify to be contacted by the Response Team.
It is voluntary for you whether you wish to interact with and provide information to the Response Team.
After completing a conversation with our proactive support team, you may be asked to complete a voluntary evaluation of the conversation. The purpose is partly to give you the opportunity to provide feedback and partly to improve our service.
Common information:
Special categories of information in the form of health information:
The personal data is received directly from you when you answer the questions in Howdy or during your interaction with our Response Team.
Your explicit consent to process general personal data (GDPR art 6(1)(a)) and special categories of personal data (art 9(2)(a))
If you live in the Asia Pacific region, a qualified partner has been chosen to handle the Response Team. Howdy ApS has secured a legal basis for the transfer by entering a contract with the chosen partner that includes “Standard Contractual Clauses”.
If you live in the United States, a qualified partner has been chosen to handle the Response Team. Howdy ApS has secured a legal basis for the transfer by entering a contract with the chosen partner that includes “Standard Contractual Clauses”. Be aware that our services are not covered by the United States Health Insurance Portability and Accountability Act.
See chapter 3.
To provide anonymous statistics to your employer.
Statistics will be based on your personal information, but always anonymous so they cannot be tracked back to you. This means that statistics will never be with categories so it can be deducted who falls into that category. It will also not be visible in the statistics whether you have enrolled in the program or not, and whether you had or have cases or not with the Response Team.
Common information:
Special categories of information in the form of health information:
The personal data concerning your answers and wellbeing and cases are received directly from you when you answer the questions in Howdy and your interaction with the response team.
GDPR art. 6 (1)(f). Our legitimate interests to provide anonymous statistics to your employer based on our agreement.
Your consent to process special categories of personal data (art 9(2)(a))
See chapter 3.
Personal data are used to produce anonymous statistics in order to improve our service, develop new relevant services as well as ensuring that we deliver the best possible service to you, your co-workers and employees of our other customers.
Common information:
Special categories of information in the form of health information:
The personal data concerning your answers and wellbeing and cases are received directly from you when you answer the questions in Howdy and from your interaction with a Response Team
GDPR art. 6 (1)(f). Our legitimate interests to improve and develop our services
Your consent to process special categories of personal data (art 9(2)(a))
See chapter 3.
Ensure security and monitoring activities in the platform, errors, intrusion, etc.
Managing cases for you or on your behalf.
User behaviour including:
Directly from you through your use of Howdy
Our legitimate interests in ensuring that the systems are running safely (GDPR art 6(1)(f))
See chapter 3.
We utilise profiling to offer the different services in Howdy. Profiling is done by an automated run-through of your answers and awarded points. Where possible, we use an underlying professional frame of reference, such as the WHO-5 to measure wellbeing and calculate a wellbeing score.
If the profiling of your answers uncovers a need for contact, our Response Team will conduct an individual and specific evaluation of your information and will, on that basis, decide if there is a need for counselling from a health professional.
It is our Response Team who conducts a professional evaluation of the information you provide us with and converts your information into reason codes and notes that are stored in our database.
It is necessary for us to utilise profiling to be able to give you the full benefits of Howdy.
Your personal data is generally deleted when your employer removes you or when the relationship between your employer and us has ended (whichever comes first).
When you withdraw your consent, we anonymise your answers and cases, so they cannot be traced back to you, but can be used in statistics. We delete the case notes (through your interaction with the Response team) though.
Security log entries are deleted 60 days after they are created.
Support cases are delete one year after your employer removes you or one year after the relationship between your employer and us has ended (whichever comes first).
We do not transfer your personal data to others.
Your employer can choose to receive statistics or not. If they choose to receive, they can setup how they would like to breakdown statistics through Howdy. It is very important to us that your employer cannot identify the person behind a wellbeing report.
We use data processors to store and process personal data on our behalf in accordance with this Policy and the applicable legislation. These data processors all act in accordance with the instructions they have received from us.
The Response Team is in most cases handled by personnel employed by us. However, in some cases the Response Team may be handled by one of our partners who act as data processor on our behalf and according to our instructions.
Howdy is hosted on servers located within the EU/EEA and thus your personal data is generally processed within the EU/EEA.
In certain limited cases we may transfer some your personal data to countries outside the EU/EEA (third countries). In such cases we will always ensure that appropriate safeguards are in place, e.g., by using the standard contractual clauses as adopted and published by the European Commission.
You have the right to obtain a copy of these clauses and safeguards. See chapter 6 on how to exercise this right.
To exercise any of your rights below, reach out to us using the contact information under chapter 1. Your rights are not absolute and may have to be balanced with the rights of others as well as the rights subject to some exceptions as a matter of law.
At any given time, you have the right to access your personal data. This means that you can request:
You may be entitled to data portability and thereby receive your information in a structured, commonly utilised, machine-readable format. This only applies where all of the following criteria are met: i) the legal basis for our processing is your consent or our contract with you, ii) the processing is carried out by automated means, and iii) the information has been provided by you about yourself.
If you are under the impression that the personal data we process about you is inaccurate or incomplete, you have the right to have them corrected.
When you do not want us to process your personal data any more, you have the right to ask us to delete your personal data.
You have the right to object to our processing of your personal data. This right only applies insofar as the legal basis for the processing is based on our legitimate interests or public interest. If we cannot demonstrate compelling legitimate grounds for continuing the processing, we will make sure to stop the relevant processing of your personal data.
Under certain circumstances you have the right to have the processing of your personal data restricted.
Where the processing of your personal data is based on your consent you have the right to withdraw your consent at any given time. You can do that in the app or by sending an email to opt-out@howdy.care. A withdrawal of consent will imply that we can no longer deliver our services to you. However, the withdrawal does not affect the legality of the processing of your personal data that took place prior to the withdrawal.
If you wish to make a complaint about our processing of your personal data, you also have the right to reach out to a supervisory authority. Below you will find contact information for the Danish Data Protection Agency (Datatilsynet):
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Phone no.: +45 33193200
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
This Policy is reviewed on a continuous basis to make sure it is up to date. Thus, we reserve the right at any given time to amend this Policy and in case any material amendments are made we will inform you in the app. The applicable Policy is accessible on Howdy at any given time.
This Policy version 3 was last amended in February 2021 and replaces any previous versions.