Summary of Privacy Policy

To view the full privacy policy, go here – https://smartrespiratory.com/privacy-policy

GDPR Compliance statement

We are committed to ensuring the security and protection of the personal information we process, maintaining a compliant approach to data protection. We acknowledge our obligations under the EU General Data Protection Regulation (“GDPR”) effective since 25 May 2018, and the UK’s Data Protection Bill.

We are dedicated to safeguarding personal information under our control and maintaining a system that meets GDPR requirements. Key aspects of our approach include:

All personal data is stored anonymously with two-step encryption and access limitations. Data security is assured by Google Firebase services, which are ISO 27001 and SOC 1, SOC 2, SOC 3 certified, with some also ISO 27017 and ISO 27018 certified.

We only collect necessary user-related information approved by our users or customers for essential operations. All stored personal data will be deleted upon user request.

Our procedures include safeguards to promptly identify, assess, investigate, and report any personal data breaches. These procedures are communicated to all employees.

We have enhanced consent mechanisms to ensure individuals understand what data they provide, why and how we use it, and provide clear ways to consent to data processing.

We are reviewing our retention policy to comply with the ‘data minimization’ and ‘storage limitation’ principles. Personal information is stored, archived, and ethically destroyed. Erasure procedures are in place, and we adhere to data subject rights, exemptions, response timeframes, and notification responsibilities.

How we use your data

Smart Respiratory Products Ltd. (SRP) requires your data to enable you to track and chart your peak flow, inhaler use, symptoms, and added notes. We conduct data back-ups to prevent data loss in case of device changes or loss. Your de-identified data is linked to a randomly generated ID, ensuring complete anonymity as it is not linked to your email address. Please note that if you forget your login details, retrieving your data from the Cloud is not possible due to our security measures.

You can share your asthma data with your doctor or anyone via email as a PDF chart or Excel spreadsheet using the app’s share function. Alternatively, real-time sharing through the Smart Asthma console provides your doctor with valuable insights into your asthma condition. By registering for this service and scanning your doctor’s QR code, you authorise your doctor or the responsible person in your clinical programme to view your data on a dashboard and you create an ID for identification purposes, enabling them to monitor and assess your results, which may help in adjusting your medication as needed. However, sharing does not guarantee that your doctor or clinician will review your data outside of consultations. It remains your responsibility to self-monitor and communicate with your doctor or clinician as necessary.

The shared data is encrypted, and only the authorised person can access it. It is their responsibility to manage this access securely. You have the option to stop sharing your data with your doctor or clinician at any time, and request deletion of all stored data.

Please be aware that while we take reasonable steps to protect your information, no website, internet transmission, computer system, or wireless connection is entirely secure.

Data handling

Data generated by the Smart Peak Flow (SPF) device and recorded in the app is encrypted and securely stored on a UK-based server in the Google Cloud. The primary purpose of storing this data is to allow asthmatics to monitor their own asthma data.

SRP utilises only de-identified or anonymous patient data for user services, research, development, medical purposes, and service improvements. Stakeholders do not have access to identifiable user data. Terms & Conditions explicitly forbid stakeholders from selling data to third parties. Only SRP members have access to the data recorded in the app.

When signing up for data sharing with the Smart Asthma Console, the patient authorises the doctor or clinical programme to receive their recorded data, including names or unique identifiers necessary for monitoring. This authorization can be withdrawn at any time, and only the doctor / clinician has access to this information. Before enabling this sharing function, you will be prompted to read and accept the detailed privacy policy regarding live data sharing in the app. 

To view the full privacy policy, go here – https://smartrespiratory.com/privacy-policy