HealthReact Privacy Policy
Effective: August 3, 2026
Last updated: August 3, 2026
This Privacy Policy explains how HealthReact processes personal data in connection with the HealthReact research platform, HealthReact mobile application, web portals, dashboards, connected wearable and sensor integrations, and related services.
HealthReact is a digital research platform used to support scientific, clinical, public health, behavioural, and health-related studies. Depending on the specific study, HealthReact may collect questionnaire data, passive smartphone data, wearable device data, health and fitness data, and other study-related information.
This Privacy Policy also explains how HealthReact accesses, uses, stores, secures, shares, and deletes data obtained from Google APIs, including Google Health API and Fitbit-related data accessible through Google Health API.
1. Provider information
HealthReact is provided by:
University of Hradec Kralove
Faculty of Science
Rokitanskeho 62
500 03 Hradec Kralove
Czech Republic
Company ID: 62690094
Contact e-mail: info [at] healthreact.eu
Data protection contact: gdpr [at] uhk.cz
If HealthReact is provided in a particular study by another organisation or in cooperation with another organisation, the study-specific information sheet, informed consent form, contract, or study documentation will identify the relevant controller, processor, study sponsor, research institution, and contact details.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- the HealthReact mobile application,
- HealthReact web portals and dashboards,
- study workspaces operated through HealthReact,
- integrations with connected wearable devices and services,
- integrations with Google Health API and Fitbit-related data sources,
- data processing necessary to provide, operate, secure, and support HealthReact.
Individual studies may have additional privacy notices, informed consent forms, participant information sheets, ethics approval documentation, or contractual terms. If such study-specific documents provide more specific information, they apply in addition to this Privacy Policy.
3. Role of HealthReact in data processing
HealthReact may process personal data in different roles depending on the specific study and contractual arrangement.
In many studies, the research institution, healthcare provider, university, study sponsor, or other organisation responsible for the study acts as the data controller. In such cases, HealthReact acts as a data processor and processes data on behalf of the controller and according to its instructions.
In some cases, the University of Hradec Kralove or another research institution may act as the controller or joint controller. The applicable role will be specified in the relevant study documentation, agreement, or participant information materials.
HealthReact does not determine the scientific purpose of each individual study unless explicitly stated in the study documentation.
Google Health API connections are operated centrally by the University of Hradec Kralove through the HealthReact Google Fetcher. The Google Fetcher may support multiple studies, but each connection and data flow is assigned to one specific study, workspace, and pseudonymous participant. The institution responsible for each study and the respective roles of the parties are identified in the study-specific documentation.
4. Categories of data we may process
The exact categories of data depend on the specific study, enabled HealthReact modules, participant consent, connected devices, and selected integrations.
HealthReact may process the following categories of data:
4.1 Account, identification, and study enrolment data
This may include:
- internal participant identifier,
- study identifier,
- workspace identifier,
- pseudonymous user ID,
- study group or cohort assignment,
- enrolment status,
- device registration status,
- technical account identifiers,
- contact information where required by the study.
In many studies, HealthReact uses pseudonymous identifiers rather than directly identifying participant names.
4.2 Questionnaire and self-reported data
Depending on the study, HealthReact may collect:
- answers to questionnaires,
- ecological momentary assessment data,
- daily diary entries,
- symptom reports,
- mood, stress, pain, fatigue, sleep quality, or behavioural reports,
- lifestyle, nutrition, physical activity, or treatment adherence reports,
- timestamps of responses,
- compliance and completion data.
4.3 Passive smartphone and application data
Depending on the study and enabled permissions, HealthReact may process:
- app usage and interaction data,
- questionnaire completion events,
- notification delivery and response data,
- technical device information,
- operating system information,
- application version,
- error logs,
- connectivity information,
- sensor-derived information where enabled by the study and device settings.
If enabled by the specific study and authorised by the participant, HealthReact or related components may collect location data, including GPS-based data, for research purposes such as mobility analysis, context detection, time-location patterns, or study-specific behavioural analysis.
4.4 Wearable device, sensor, and health-related data
HealthReact may receive or process data from wearable devices, sensors, mobile applications, and connected health services, depending on the specific study and participant consent.
Such data may include:
- physical activity,
- steps,
- distance,
- energy expenditure,
- heart rate,
- heart rate variability,
- sleep duration,
- sleep stages or sleep-related metrics,
- resting heart rate,
- breathing-related metrics,
- movement and accelerometer-derived data,
- body measurements,
- device status,
- data availability and synchronization status,
- other health, fitness, behavioural, or physiological metrics required by the study.
The exact data types depend on the connected device, service provider, API availability, participant consent, and study protocol.
4.5 Data from Google Health API, Fitbit, and connected Google services
If an eligible adult participant chooses to connect Google Health API, HealthReact may access health and fitness data from Google APIs only after the participant has received the study-specific disclosure, provided the required consent, and granted permission through Google OAuth.
The HealthReact Google OAuth application is configured for the following read-only Google Health API scopes:
googlehealth.activity_and_fitness.readonlyfor study-required activity and fitness data, which may include steps, distance, active minutes, energy expenditure, exercise sessions, sedentary periods, floors, swimming data, altitude, VO2 max, and time in heart-rate zones;googlehealth.health_metrics_and_measurements.readonlyfor study-required health metrics and measurements, which may include heart rate, heart rate variability, resting heart rate, heart-rate zones, oxygen saturation, respiratory metrics, temperature-related metrics, height, weight, body fat, and blood glucose where specifically required by the study; andgooglehealth.sleep.readonlyfor study-required sleep sessions, sleep duration, sleep stages, and related sleep information.
These scopes are permission bundles made available by Google. HealthReact requests from each participant only the subset of these scopes that is necessary for the specific study and retrieves only the data types described in the relevant study documentation and consent. HealthReact does not request Google Health API write permissions.
HealthReact also processes the Google Health user identifier and, where necessary for migration from the legacy Fitbit Web API, the legacy Fitbit user identifier. These identifiers are used only to associate the connection with the correct pseudonymous HealthReact participant and study.
HealthReact does not access Google Health API or Fitbit-related data unless the participant has explicitly authorised access through Google OAuth.
4.6 OAuth, authentication, and connection data
When a participant connects Google Health API, Fitbit-related data, or another external service, HealthReact may process technical authentication data necessary to maintain the connection, including:
- OAuth authorization codes,
- access tokens,
- refresh tokens,
- granted scopes,
- token status,
- token expiry information,
- connection timestamps,
- synchronization timestamps,
- Google user identifier,
- Fitbit or legacy Fitbit user identifier where applicable,
- audit logs related to authorization, synchronization, and revocation.
OAuth tokens are used only to access the data authorised by the participant and only for the purposes described in this Privacy Policy and the relevant study documentation. Access and refresh tokens are encrypted before being stored, and the encryption keys are managed separately from the token database.
4.7 Technical, security, and audit data
HealthReact may process technical and security data, including:
- IP address,
- browser or device information,
- server logs,
- authentication logs,
- access logs,
- error logs,
- security event logs,
- API request metadata,
- system monitoring data.
This data is used to operate, secure, debug, maintain, and improve the reliability of HealthReact.
5. How data is collected
HealthReact may collect data:
- directly from participants through the HealthReact application or web interface,
- from questionnaires and study tasks completed by participants,
- from smartphones and mobile sensors where enabled,
- from wearable devices and connected services,
- from Google APIs after participant OAuth consent,
- from Fitbit-related data sources accessible through Google Health API,
- from research staff, clinicians, or study administrators,
- automatically through system logs and technical infrastructure.
Data collection depends on the study configuration, participant consent, device permissions, and connected services.
For research studies using Google Health API, the responsible study team confirms participant eligibility and obtains the required signed informed consent before issuing the QR code or other credentials needed to enter the study in HealthReact. Before Google OAuth is initiated, HealthReact provides a separate study-specific disclosure that describes the research, the requested data, purposes, recipients, retention period, security measures, withdrawal and deletion procedures, risks, benefits, and contact details. The participant can save, download, e-mail, or otherwise retain the disclosure, the applicable informed consent documents, and any other documents required by the ethics committee. The study team provides the participant with a copy of any document that was signed only in paper form. The participant must take an affirmative action before the OAuth request proceeds.
6. Purposes of processing
HealthReact processes personal data for the following purposes, depending on the specific study and enabled functionality:
6.1 Operation of the HealthReact platform
This includes:
- creating and maintaining study workspaces,
- registering participants,
- delivering questionnaires and study tasks,
- sending study notifications and reminders,
- managing device and wearable connections,
- synchronizing data,
- providing dashboards and reports to authorised study staff,
- monitoring study compliance and data completeness.
6.2 Scientific and clinical research
HealthReact may process data for research purposes, including:
- analysis of physical activity,
- analysis of sleep and sleep regularity,
- analysis of heart rate and physiological patterns,
- behavioural and lifestyle research,
- digital phenotyping,
- ecological momentary assessment,
- intervention studies,
- longitudinal monitoring,
- evaluation of health-related outcomes,
- study-specific predefined calculations and statistical analysis.
The specific research purpose is defined in the relevant study protocol, participant information sheet, informed consent form, or other study documentation. Google Health API data is collected only for a study that has obtained approval or a waiver from an independent ethics committee or another competent review board.
6.3 Personalised study interventions and feedback
Where enabled by the study, HealthReact may use collected data to:
- trigger questionnaires,
- send reminders,
- deliver study-specific interventions,
- provide personalised feedback,
- support just-in-time adaptive interventions,
- detect relevant patterns or events defined by the study protocol.
6.4 Security, reliability, and support
HealthReact processes technical data to:
- maintain platform security,
- detect and prevent misuse,
- troubleshoot errors,
- ensure correct synchronization,
- provide technical support,
- verify system performance,
- maintain audit trails.
6.5 Legal, contractual, and compliance purposes
HealthReact may process data to:
- comply with applicable legal obligations,
- document participant consent and permissions,
- comply with contractual obligations,
- respond to lawful requests,
- support audits,
- demonstrate compliance with data protection, research, and information security requirements.
7. Legal bases for processing
The legal basis for processing personal data depends on the specific study, jurisdiction, controller, and applicable documentation.
Under the General Data Protection Regulation, the legal basis may include:
- consent of the participant,
- performance of a task carried out in the public interest,
- legitimate interests of the controller or processor,
- performance of a contract,
- compliance with legal obligations,
- scientific research purposes subject to appropriate safeguards,
- explicit consent for processing special categories of personal data,
- processing necessary for scientific research in accordance with applicable law.
The specific legal basis for each study should be stated in the study-specific participant information sheet, informed consent form, ethics documentation, or controller privacy notice.
Where Google Health API, Fitbit-related data, or other connected health service data is accessed, HealthReact accesses such data only after the participant has granted permission through the applicable authorization process.
8. Use of Google API data and Limited Use compliance
HealthReact's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
HealthReact's use of information received from Google Health API adheres to the Google Health API Developer and User Data Policy, including its Limited Use requirements.
HealthReact's use of information received from Google Health API for research adheres to the Google Health API User Data and Health Research Policy, including its Limited Use requirements.
HealthReact uses Google Health API data only for the original ethics-approved research purpose described to the participant and for visible HealthReact functionality supporting that purpose, including authorised data synchronization, study monitoring, dashboards, reports, predefined analysis, and study-specific interventions.
HealthReact does not use Google API data for advertising.
HealthReact does not sell Google API data.
HealthReact does not use Google API data for marketing profiling.
HealthReact does not transfer Google API data to advertising platforms, data brokers, or information resellers.
HealthReact does not use Google API data to determine creditworthiness, insurance eligibility, employment eligibility, or similar decisions.
HealthReact does not use Google Health API data to train artificial intelligence or machine-learning models, including general-purpose, shared, or cross-study models.
HealthReact does not use Google Health API data as part of the regulated function of a medical device, for emergency monitoring, for operational military or security purposes, for weaponry, or in any environment where use or failure of the integration could reasonably be expected to result in death, personal injury, or material damage.
HealthReact does not process Google Health API data as Protected Health Information regulated by the United States Health Insurance Portability and Accountability Act unless all applicable authorisations and any prior written approval required by Google have been obtained.
HealthReact does not allow humans to read Google API data unless one of the following applies:
- the participant has expressly consented to access by specifically identified authorised members of the study team for the original research purpose,
- access is necessary for security, abuse investigation, support, or debugging,
- access is necessary to comply with applicable law,
- the data has been appropriately aggregated and anonymised and is used for lawful internal operations.
Any access by authorised personnel is limited according to role, study, workspace, purpose, and need-to-know principles. A study controller cannot independently authorise access to Google Health API data for a new purpose that was not disclosed to and authorised by the participant, unless a lawful ethics-review waiver applies.
Garmin Connect Data
With the participant's explicit authorization, HealthReact may collect selected health, wellness, fitness, and activity data from Garmin Connect through Garmin APIs. Depending on the specific study and permissions granted by the participant, this may include physical activity, steps, distance, energy expenditure, heart rate, heart rate variability, sleep, stress, respiration, body-related metrics, activities, and related device or synchronization information.
Garmin data is collected by the HealthReact Garmin Fetcher and associated with the relevant study, workspace, and pseudonymous participant. It is used only for purposes described in the applicable study documentation, such as scientific or health-related research, monitoring, dashboards, reports, analysis of behavioural and physiological patterns, personalised feedback, and data-triggered questionnaires or interventions.
Garmin data is processed and stored within the HealthReact environment assigned to the relevant study. Access is restricted to authorised personnel. Appropriate safeguards may include encrypted transmission, encryption at rest where applicable, access controls, role-based permissions, pseudonymous identifiers, audit logs, backups, and separation of study workspaces.
Garmin data may be made available to the research institution, authorised study team, controller, processors, hosting providers, and technical service providers only where necessary to operate or support HealthReact or carry out the relevant study. Such recipients and processors are identified in the applicable study documentation where required. Garmin data is not sold, used for advertising, or shared with unrelated third parties.
Garmin data is not used by default to train general-purpose or shared artificial intelligence or machine-learning models, and data from separate studies is not combined for such training.
A specific research project may use Garmin data for study-specific automated analysis, personalised AI-assisted communication or interventions, or for the development, training, or validation of a study-specific model. Such processing is carried out only where necessary for the approved research purpose, described in the study documentation and participant information, and supported by the applicable legal basis, consent, and ethical approval.
Where Garmin data is processed by a third-party artificial intelligence or data-processing provider, the provider, purpose of processing, categories of data, and applicable safeguards are identified in the relevant study documentation before processing begins. Contracted providers may process the data only on documented instructions and may not use it to train their own general-purpose or shared models.
Participants may disconnect Garmin Connect or revoke the relevant permissions through the available Garmin or HealthReact settings. This stops future collection from the disconnected Garmin connection. Previously collected data is retained or deleted according to the applicable study documentation, legal basis, controller instructions, and this Privacy Policy.
9. Data sharing and recipients
HealthReact may share or make personal data available only where necessary and in accordance with the applicable study documentation, contracts, participant consent, and legal requirements.
Recipients may include:
- the research institution responsible for the study,
- authorised study investigators,
- authorised clinicians or healthcare professionals involved in the study,
- authorised study administrators,
- the University of Hradec Kralove personnel who operate, secure, and support HealthReact, subject to role-based access and confidentiality obligations,
- Google Cloud Platform, used by the University of Hradec Kralove to host the central Google Fetcher, encrypted databases, key-management services, secrets, backups, monitoring, and audit logs in an EU region,
- other processors or technical providers specifically identified in the applicable study documentation before data is transferred to them,
- ethics, regulatory, or auditing bodies where required,
- public authorities where legally required.
HealthReact does not sell personal data.
HealthReact does not sell Google API data or Fitbit-related data.
HealthReact does not share Google API data with advertisers or marketing platforms.
Google Health API data is transferred to a third party only where necessary for the original research purpose, where the participant has expressly consented to the transfer of the relevant data, and where the recipient is contractually bound to use the data only for that purpose, or where transfer is necessary for security or required by law. The specific study controller, authorised study team, recipients, and processors are identified in the study-specific documentation.
HealthReact does not share identifiable or pseudonymous participant data between separate study workspaces or reuse it in another study without separate participant consent, unless an ethics committee or competent review board has expressly waived the requirement for separate consent in accordance with applicable law.
Research publications and presentations based on Google Health API data contain only appropriately aggregated or de-identified findings and do not identify individual participants. The responsible study publicly identifies the relevant Google or Fitbit data source and notifies Fitbit for the study's inclusion in the Fitbit Publication Library.
10. Study workspace separation
HealthReact is used in multiple studies. Studies may be operated on separate servers or within separate HealthReact workspaces on shared infrastructure.
HealthReact applies technical and organisational measures to separate studies and workspaces. Users authorised for one study or workspace do not automatically have access to data from another study or workspace.
The central Google Fetcher may support multiple studies. Each Google Health connection is bound server-side to one study, one destination HealthReact environment, and one pseudonymous participant. The destination is not selected from untrusted information received from the mobile application or OAuth callback. The Fetcher routes data only according to the validated internal connection record.
HealthReact pseudonymises and otherwise de-identifies Google Health API participant data to the greatest extent compatible with the approved study purpose and required data routing.
Data is associated with internal identifiers such as:
- participant ID,
- workspace ID,
- study ID,
- tenant ID,
- device connection ID.
This separation is used to ensure that data collected for one study is not accessible to unauthorised users from another study.
11. Storage and security of data
HealthReact applies technical and organisational security measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
These measures include:
- encrypted communication using modern HTTPS/TLS protocols,
- encryption of Google Health API data at rest, including databases and backups,
- application-level authenticated encryption of Google OAuth access and refresh tokens before database storage,
- separate management, access control, auditing, and rotation of encryption keys through Google Cloud Key Management Service or an equivalent-strength key-management system,
- access control,
- role-based permissions,
- multi-factor authentication for privileged access,
- authentication and authorization mechanisms,
- pseudonymisation where appropriate,
- separation of study workspaces,
- authenticated server-to-server communication between the Google Fetcher and the relevant HealthReact environment,
- prohibition of OAuth tokens in application logs, error messages, and diagnostic exports,
- logging and audit trails,
- server monitoring,
- encrypted backup and recovery procedures,
- restricted administrative access,
- staff confidentiality obligations,
- vulnerability management, security review, incident response, and maintenance procedures.
OAuth access tokens and refresh tokens are stored in encrypted form and used only to maintain authorised data access. Encryption keys are not stored in the same database as the encrypted tokens. Access to tokens and keys is restricted to systems and personnel that require access for platform operation, security, support, or compliance purposes and is logged where technically applicable.
HealthReact maintains an incident response process. Known or suspected unauthorised access affecting Google data is handled in accordance with applicable law, study obligations, and the notification requirements of Google Health API policies.
No method of transmission or storage is completely secure. HealthReact continuously works to maintain appropriate safeguards according to the nature of the data and the risks involved.
12. Data retention
Personal data is retained only for as long as necessary for the purposes described in this Privacy Policy, the relevant study documentation, contractual requirements, legal obligations, research integrity requirements, or applicable retention policies.
Retention periods may differ between studies.
In general:
- study data is retained according to the study protocol, contract, ethics approval, or legal requirements,
- technical logs are retained for a limited period necessary for security, debugging, and audit purposes,
- OAuth tokens are retained only while the participant's Google Health connection remains active and the connection is needed for the approved study,
- data may be deleted, anonymised, or archived after the relevant retention period.
If a participant disconnects Google Health API, revokes Google OAuth access, withdraws from the relevant data collection, or is removed from the study, HealthReact stops collecting new data from that connection and deletes the stored OAuth tokens when they are no longer required to complete the revocation process or comply with a legal obligation.
Previously collected Google Health API data will be deleted on a valid request where applicable. Some data may need to be retained, restricted, anonymised, or excluded from future research rather than deleted where deletion is not permitted or is not technically possible because of applicable law, ethics-approved study design, research-integrity requirements, an already completed analysis, or publication in a properly anonymised form. The applicable limitations and retention period are explained in the study-specific documentation before participation.
13. Participant choices and control
Depending on the study, applicable law, and application configuration, participants may have the ability to:
- refuse participation in a study,
- withdraw from a study,
- skip optional questionnaires,
- disable certain mobile permissions,
- disconnect a wearable device or external service,
- revoke Google OAuth access,
- request access to their data,
- request correction of inaccurate data,
- request deletion where legally applicable,
- object to processing where legally applicable,
- request restriction of processing where legally applicable,
- contact the study team or data controller with privacy questions.
Participants can revoke Google API access through their Google Account settings for connected third-party applications. If Google Health API or Fitbit-related access is revoked, HealthReact will no longer be able to retrieve new data from that Google connection.
Participants may also request disconnection, withdrawal, or deletion through the contact details provided by the responsible study team. If those details are unavailable, a request may be sent to info [at] healthreact.eu. A request should identify the study and provide the participant identifier or other information reasonably necessary to locate the connection; participants must never send their Google password or OAuth tokens. HealthReact or the responsible controller may need to verify the request before acting on it.
Revoking Google API access stops future retrieval but does not by itself delete data already collected and stored in HealthReact. A participant who also wants previously collected data deleted must follow the study withdrawal or deletion process. HealthReact will delete, restrict, anonymise, or exclude the data from future research as required by the applicable study documentation and law and will inform the participant or controller if an exception prevents full deletion.
14. International transfers
HealthReact primarily processes and stores data within the European Union or European Economic Area. The central Google Fetcher and its supporting databases, key-management services, secrets, backups, monitoring, and audit logs are operated by the University of Hradec Kralove using Google Cloud Platform resources configured in an EU region.
Google Health API data may be transmitted from the central Google Fetcher to the HealthReact server or workspace assigned to the participant's study. The destination environment and any relevant hosting provider are identified in the study-specific documentation and must meet the security requirements described in this Privacy Policy.
If data is transferred outside the European Union or European Economic Area, such transfer will be carried out in accordance with applicable data protection laws and appropriate safeguards, such as adequacy decisions, standard contractual clauses, contractual safeguards, or other legally recognised mechanisms.
The specific hosting location and transfer arrangements may depend on the study, controller, infrastructure, and contractual setup.
15. Children and minors
HealthReact may be used in studies involving children or minors only where the relevant study has appropriate ethical, legal, parental, guardian, institutional, or participant consent arrangements in place.
The specific rules for participation of minors are defined by the relevant study documentation, ethics approval, and applicable law.
HealthReact does not knowingly collect data from children outside a valid study, legal, or consent framework.
The Google Health API integration described in this Privacy Policy is enabled only for participants who are at least 18 years old. Studies involving minors must use other approved data-collection methods unless HealthReact completes a separate legal, ethical, technical, and Google policy review for such use.
16. Automated processing and profiling
HealthReact may perform automated data processing to support study functionality, such as:
- detecting missing data,
- calculating compliance,
- generating dashboards,
- deriving digital biomarkers or study variables,
- triggering questionnaires,
- sending reminders,
- supporting study-specific interventions.
The specific automated processing depends on the study configuration.
HealthReact does not use Google API data or Fitbit-related data for advertising profiling, marketing profiling, credit scoring, insurance eligibility, employment eligibility, or similar decisions.
Google Health API data is not used to train artificial intelligence or machine-learning models. It is not combined across studies for model training, commercial profiling, or the creation of general-purpose datasets.
If a study uses automated processing that may significantly affect participants, this will be described in the relevant study documentation.
17. Data accuracy and limitations
HealthReact may process data received from third-party devices, applications, and APIs. Such data may depend on:
- device accuracy,
- sensor availability,
- participant behaviour,
- synchronization frequency,
- manufacturer algorithms,
- API availability,
- permissions granted by the participant,
- network connectivity,
- device battery status.
HealthReact does not guarantee that data from third-party devices or services is complete, continuous, clinically accurate, or suitable for diagnosis.
HealthReact is generally intended for research and monitoring purposes and is not a medical diagnostic tool. Google Health API data is not used for the regulated function of a medical device, emergency monitoring, or clinical decision-making.
18. Third-party services
HealthReact may integrate with third-party services, devices, or APIs. These services may have their own privacy policies, terms of service, and account settings.
Such services may include, depending on the study:
- Google Health API,
- Fitbit-related data sources,
- Google Cloud Platform infrastructure used for the central Google Fetcher and related security and storage services,
- Garmin-related services or SDK-based integrations,
- continuous glucose monitoring services,
- smart scales,
- environmental sensors,
- mobile operating system services,
- other wearable, sensor, or health data providers.
Participants should review the privacy policies of any third-party services they connect to HealthReact.
HealthReact is responsible for the processing it performs after receiving data from third-party services. The third-party provider remains responsible for its own processing according to its own policies and terms.
19. Withdrawal of consent and study withdrawal
Participants may be able to withdraw consent or withdraw from a study, depending on the study design and applicable legal basis.
Withdrawal may affect future data collection, access to HealthReact, or continued participation in the study.
Withdrawal does not necessarily affect processing that occurred before withdrawal if such processing was lawful at the time. Previously collected data may continue to be processed where permitted by applicable law, study documentation, research integrity requirements, or controller instructions.
Participants should contact the relevant study team or controller for study-specific withdrawal and deletion procedures. If the study contact is unavailable, participants may contact info [at] healthreact.eu. Withdrawal includes stopping future collection and provides an option to request deletion of personal data or, where deletion is not permitted or possible, removal from future research and appropriate restriction or anonymisation.
20. Rights of data subjects
Under applicable data protection laws, including the GDPR where applicable, participants may have rights such as:
- the right of access,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to object,
- the right to data portability,
- the right to withdraw consent where processing is based on consent,
- the right to lodge a complaint with a supervisory authority.
The availability and scope of these rights may depend on the legal basis, study context, applicable law, and whether HealthReact acts as controller or processor.
If HealthReact acts as a processor, requests may need to be handled by the relevant study controller.
21. Supervisory authority
Participants in the Czech Republic may contact the Czech data protection supervisory authority:
Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
Website: https://www.uoou.cz
Participants may also have the right to contact another competent supervisory authority depending on their country of residence, place of work, or place of the alleged infringement.
22. Changes to this Privacy Policy
HealthReact may update this Privacy Policy from time to time to reflect changes in the platform, legal requirements, Google API requirements, study practices, or technical integrations.
The latest version will be published on the HealthReact website. If changes are material, HealthReact or the relevant study controller may provide additional notice where required.
If HealthReact proposes to use Google Health API data for a new purpose that was not previously disclosed and authorised, the relevant privacy information and study documentation will be updated and a new consent or other valid ethics-reviewed authorisation will be obtained before the new use begins.
23. Contact
For privacy-related questions about HealthReact, please contact:
HealthReact Privacy Contact
E-mail: info [at] healthreact.eu
For questions about a specific study, participants should contact the study team or controller identified in the study documentation.
