Privacy Policy
Last updated: March 25, 2026
At Bluebow , we place paramount importance on the protection of your personal and health data. This policy details how we collect, use, and secure your information in strict compliance with the General Data Protection Regulation ( GDPR ).
1. Data Collection
We only collect the information necessary for the proper functioning of our services:
-
Identification data : Name, surname, email address.
-
Usage data : Information about your browsing and interactions with our wellness programs.
-
Health data : As part of our protocols (CBT, EFT), responses to questionnaires are processed with enhanced security.
2. Use of your data
Your data is used exclusively for:
-
Providing and personalizing our mental health services.
-
To ensure therapeutic follow-up between practitioners and their patients.
-
Improving the effectiveness of our programs through anonymized statistical analyses.
3. Protection and Security
Bluebow implements rigorous technical and organizational security measures:
-
End-to-end data encryption.
-
Hosting on secure servers that meet health data protection standards.
-
Access strictly limited to authorized personnel.
4. Data sharing
We never sell or rent your personal data to third parties. Your information is only shared in the following cases:
-
With your explicit consent, for the coordination of care with your healthcare professional.
-
To comply with legal or regulatory obligations.
5. Your rights
In accordance with the GDPR, you have the following rights:
-
Right of access and rectification of your data.
-
Right to erasure (right to be forgotten).
-
Right to data portability.
-
You have the right to withdraw your consent at any time.
6. Data Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, in accordance with applicable legal and regulatory requirements:
-
Account data (name, email): retained for the duration of your use of the service and deleted within 3 years after your last activity.
-
Usage data: retained for 12 months for analytics and service improvement purposes.
-
Health data: retained for the duration of the therapeutic follow-up, then securely archived for up to 10 years, in accordance with applicable health data regulations.
-
Data related to legal obligations: may be retained longer if required by law.
At the end of these periods, data is permanently deleted or irreversibly anonymized.
7. Data Hosting
Your data is hosted within the European Union by providers that comply with GDPR and ensure a high level of security and confidentiality.
8. Contact
For any questions relating to the management of your data or to exercise your rights, you can contact our Data Protection Officer (DPO) via our Contact page.
