Privacy Statement HeartEye App and Related Cloud Service
Published by: HeartEye B.V.
Technology Provider: Orikami B.V.
Version: 1.0
Date: May 18, 2026
This Privacy Statement explains how personal data is processed when you use the HeartEye app (the “App”) and the related cloud service (the “Service”).
1. Who is Responsible (Controller / Processor Roles)
The App and cloud service are provided by HeartEye B.V., Bos en Lommerplein 280, 1055 RW Amsterdam, The Netherlands (“HeartEye”, “we”).
-
Data Controller: HeartEye controls the personal data of the HeartEye Customer to be able to provide access to the HeartEye app (the “App”) and related cloud service (the “Service”).
-
Data Processor: HeartEye processes personal data as a data processor on behalf of the HeartEye Customer, including hosting, maintenance, security, and support, under a data processing agreement with our HeartEye Customer.
2. Legal Bases
Which legal basis applies depends on the controller and the purpose:
-
Some processing is necessary to provide the Service (e.g., account creation and secure login). Without such processing, the App or specific features may not function.
3. What Personal Data is Processed (and Why)
A) Account and Security Data (Authentication and Secure Access)
For authentication and account security, we process:
-
E-mail address and password (password stored in encrypted/hashed form);
-
Invitation/verification dates and the dates on which you accepted in-app notices (e.g., this Privacy Statement);
-
Recent login history (including timestamps and IP address);
-
Last login date and last password change date;
-
Technical information needed for authentication (e.g., device/app context).
B) Data Sharing
-
Within the System: Data is shared by the HeartEye ECG Recorder for the HeartEye app for access to ECG measurements by our HeartEye Customer.
-
External Sharing: ECG reports are communicated to and stored in the HeartEye Cloud (ISO/IEC 27001 and NEN 7510) for access by authorized healthcare professionals.
C) Optional Profile Information (Only If You Provide It)
If you complete your profile page, we may process:
-
Your name (for support and personalisation).
We do not use automated decision-making producing legal effects or similarly significant effects solely based on automated processing.
4. With Whom Do We Share Your Data
Service Providers: HeartEye uses IT service providers for hosting, database services, monitoring/analytics, and support tooling.
Our (sub)processor/technology providers are:
-
Orikami B.V.
-
Google Cloud EMEA Limited
-
Okta, Inc. (Auth0)
-
MongoDB Inc.
-
PostHog Inc. (Cloud EU)
We put appropriate contractual safeguards in place (such as data processing agreements) and require appropriate security measures. Information about our (sub)processors is available on request via
support@hearteye.nl.HeartEye Customers may also download cloud-stored data and store this data in their own systems (e.g., Electronic Patient Records) under their own privacy policies and responsibilities.
5. Where is Your Data Stored and International Transfers
We aim to host and process data within the European Economic Area (EEA). Some service providers may be headquartered outside the EEA. Where an international transfer applies, we use appropriate safeguards (e.g., Standard Contractual Clauses and/or other legally valid transfer mechanisms, where applicable).
6. Data Retention
We keep your data for a minimum of five (5) years after your last usage or after termination of your account, unless a different period is required by the HeartEye Customer for a specific care pathway or study, or applicable law requires a different period.
In these cases, the retention period defined in the participant documentation as received by the HeartEye Customer applies. At the end of the applicable retention period, data will be erased or anonymised where appropriate.
7. Security
We take appropriate technical and organisational measures to protect personal data, including access controls and encryption in transit and at rest.
8. How to Contact Us / Exercising Rights
If your request relates to a project where the HeartEye Customer is the controller, we may refer you (back) to the HeartEye Customer.
-
Email: support@hearteye.nl
To verify identity, we may ask for necessary and proportionate information. If you provide a copy of an ID document, please cover your photo, passport number, and BSN. If you are not satisfied, you can contact the relevant supervisory authority.
9. Changes to This Privacy Statement
This Privacy Statement may be changed from time to time. Changes will be announced via the App and/or the HeartEye Cloud and/or email and/or via
www.hearteye.nl/privacy.
