How Smart Lifestyle handles the professional User’s own account, security and service-administration data. Audience: clinical nutritionists, clinic administrators and authorised staff.
1.Scope and controller
This notice concerns the personal data of clinical nutritionists, clinic administrators, authorised staff and business contacts who use or administer SmartEating for a clinic (professional Users). Smart Lifestyle AS, organisation number 829 972 972, c/o Christoffer Riseng Bølla, Strandvegen 107, 2315 Hamar, Norway, is controller for the account, security, service-administration and business-contact processing described here. Contact: support@smarteating.ai or +47 45 84 94 84.
Separate patient role. This is not the Patient Privacy Notice. When a professional User handles patient and clinical information for a clinic, the clinic is normally the controller and Smart Lifestyle acts as its processor. Patient-data processing is governed by the clinic’s information to patients and the clinic’s data processing agreement with Smart Lifestyle.
This document is a draft and is not effective until adopted. The currently documented pilot is for synthetic patient data only.
2.Professional User data
| Category | Examples |
|---|---|
| Identity and contact | Name, verified email, identity-provider identifier, locale and contact information. |
| Clinic and professional role | Clinic membership, role, invitations, permissions and professional relationship information. |
| Account and settings | Profile settings, language, session and authentication information. |
| Use and support | Feature events, usage totals, timestamps, support correspondence and service feedback. |
| Security and audit | IP address, device and browser information, authentication events, access actions, errors and incident records. |
| Business administration | Customer contacts, agreement administration, plan, invoicing and legal correspondence. |
A professional User’s prompts or records may contain information about patients. That patient content is not reclassified as the professional User’s own account data merely because the professional entered it; the clinic’s controller role still applies.
3.Sources
- Directly from the professional User.
- From the clinic, including invitations, roles and organisation settings.
- From the identity and authentication service.
- From use of the Service, devices, browsers, support requests and security events.
- From agreements and ordinary business communication.
4.Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Create accounts and administer clinic access | Performance of the Customer agreement and legitimate interests in providing authorised access. |
| Provide, support and improve the Service | Performance of the agreement and legitimate interests in operating a reliable professional service. |
| Protect accounts, patients and the Service | Legitimate interests in security, fraud prevention and incident response; legal obligations where applicable. |
| Measure usage and apply agreed limits | Performance of the agreement and legitimate interests in capacity and cost management. |
| Maintain accountability and handle claims | Legal obligations and legitimate interests in auditability, compliance and legal claims. |
| Administer contracts and invoicing | Performance of the agreement and accounting or other legal obligations. |
Smart Lifestyle does not sell professional User data or use it for behavioural advertising. Patient or confidential content is not used to train a general-purpose model for Smart Lifestyle’s own purposes.
5.Recipients
Professional User data is shared only where needed with relevant categories of recipients: the User’s clinic and authorised colleagues; cloud hosting, storage, security and support providers; identity and authentication providers; model or speech providers for a function the User requests; professional advisers and incident responders; and public authorities where disclosure is legally required.
The clinic receives information needed to administer its Users and meet its responsibilities. Service providers receive only the data reasonably needed for their function and are subject to appropriate contractual or legal safeguards. Current named processors are maintained in the Customer’s data processing and subprocessor information rather than repeated in this public notice.
6.International transfers
Smart Lifestyle aims to use EEA-based processing for the clinical service. Some account, support or optional service providers may process data outside the EEA. Where no adequacy decision applies, an approved transfer mechanism such as the European Commission’s Standard Contractual Clauses is used with supplementary measures where required.
7.Retention
| Data | Retention criterion |
|---|---|
| Account and clinic profile | While access or the Customer relationship is active, then as needed to close access and handle legal obligations or claims. |
| Support and business communication | For the time needed to resolve the matter and document the business relationship. |
| Security and audit records | For the time reasonably necessary to investigate incidents, document access and meet security or legal duties. |
| Usage records | For the agreement and the period needed for capacity, invoicing, accountability and claims, using event data rather than content where sufficient. |
| Accounting records | For the periods required by accounting and tax law. |
| Backups | Until overwritten in the controlled backup cycle, unless preservation is required for recovery, security or law. |
8.Security
Safeguards include verified authentication, role and organisation controls, encrypted network connections, protection of selected sensitive fields and credentials, audit logging, input and rate limits, secret management and separation between platform-administration and clinical access. No service is completely secure. Users must protect devices and authentication factors and report suspected loss or unauthorised access promptly.
9.Rights
Depending on the circumstances, a professional User may have rights to information, access, correction, deletion, restriction, objection, portability and a complaint to a supervisory authority. Requests concerning the User’s own SmartEating account may be sent to support@smarteating.ai. Requests concerning patient records must be directed to the relevant clinic.
A complaint may be submitted to the Norwegian Data Protection Authority at www.datatilsynet.no. A person in another EEA country may also contact the local supervisory authority.
10.Browser storage, changes and contact
The web workspace and identity service use cookies, local storage or similar technology needed for sign-in, session security, clinic selection, language and core settings. The clinical workspace does not currently use behavioural advertising cookies. Non-essential tracking will not be introduced without updated information and consent where required.
This notice will be updated when professional User processing materially changes. Questions may be sent to support@smarteating.ai or Smart Lifestyle AS, c/o Christoffer Riseng Bølla, Strandvegen 107, 2315 Hamar, Norway.