Gratiago Back to home
Legal · Privacy policy

User privacy policy

Last updated: May 2026
Part I — General information

Article 1 — Identity of the data controller

Data controller: Gratiago SRL.

Registered office: Belgium.

Business activity: Gratiago SRL develops and operates a digital platform that enables users to record, organise, review and manage information relating to treatment adherence and related platform interactions.

Role under the GDPR: for the processing activities carried out within the Gratiago platform, Gratiago SRL acts as data controller and determines the purposes and means of the processing of personal data within the platform.

Data Protection Officer: Miguel Azevedo.

Contact: privacy@gratiago.com.

Article 2 — Scope of this privacy policy

This Privacy Policy applies to the processing of personal data carried out by Gratiago SRL in connection with the operation and use of the Gratiago platform.

It applies to users of the Gratiago application, healthcare professionals accessing functionality made available through the platform, and personal data processed for account management, authentication, access control, platform operation, support, security monitoring, service improvement and other activities necessary to provide and govern the platform.

It covers personal data provided directly by users, data generated through use of the platform, and data collected, stored, organised, structured, displayed, analysed or otherwise processed within the Gratiago platform environment. It also covers processing carried out by service providers acting on behalf of Gratiago SRL.

This Privacy Policy does not apply to processing carried out independently by healthcare professionals, healthcare institutions or other third parties outside the Gratiago platform, where those parties determine their own purposes and means of processing.

It also does not apply to data that has been irreversibly anonymised, where no individual can be identified directly or indirectly by any means reasonably likely to be used. Data that is pseudonymised, masked, aggregated, tokenised or otherwise transformed remains subject to the GDPR where re-identification remains reasonably possible.

Part II — Processing activities and categories of data

Article 3 — Processing activities covered by this policy

The processing activities covered by this Privacy Policy are documented and maintained in Gratiago's Privacy Information Management System (PIMS), implemented through its Jira and Confluence environment.

Gratiago maintains a Record of Processing Activities (RoPA) in accordance with Article 30 GDPR and has performed a Data Protection Impact Assessment (DPIA) in accordance with Article 35 GDPR. Together, these records document the platform's processing activities, purposes, categories of data and data subjects, recipients, retention criteria, legal bases, safeguards, data flows, risks and mitigation measures.

The activities covered include account creation, authentication, modification and deletion; medication and adherence tracking; questionnaire data collection; side effect and health-related input; user notes and personal entries; behavioural analytics and interaction data; aggregated reporting; and data access, administration, support and security monitoring.

Article 4 — Categories of personal data processed

Gratiago processes personal data only where necessary for the purposes described in this Privacy Policy and documented in the RoPA and DPIA.

Account and identification data

Data required to create, manage, authenticate, secure and administer accounts: first name, last name, email address, account identifier, authentication information, account status, language preference, user role, and records relating to account creation, modification or deletion.

Healthcare professional data

Where healthcare professionals access functionality through the platform: name, professional email address, professional telephone number, professional title, specialty, institution or organisation, and professional registration or identification number where applicable.

Medication and adherence data

Data entered by users in relation to adherence and medication use: medication name or type, treatment schedule, dose timing, recorded or missed intake, adherence history, changes, reminders and user-configured routines. Where such data relates to physical or mental health, Gratiago treats it as health data and therefore as special category data under Article 9 GDPR.

Questionnaire, health input and side effect data

Data voluntarily entered through forms or questionnaires: responses, side effects, symptoms, health-related observations and self-reported treatment experience. Where it reveals health status, it is treated as special category data under Article 9 GDPR.

User notes and personal entries

Users may enter notes or other personal information, which may include personal data, health-related information or other sensitive information. Users should not enter personal data about other individuals unless this is necessary, appropriate and lawful.

Technical, usage and security data

Data required to operate, secure, maintain, troubleshoot and improve the platform: IP address, device information, application version, session metadata, timestamps, login and access logs, usage patterns, interaction events, error logs and security or audit logs.

Behavioural and derived data

Data generated through use: frequency of use, interaction patterns, adherence behaviour, changes over time, and derived views, summaries or structured representations of user-entered data. Where it can be linked to an account or reveal health information, it is treated as personal data and, where applicable, as special category data.

Aggregated, pseudonymised, masked and tokenised data

Gratiago may apply aggregation, pseudonymisation, masking or tokenisation to reduce exposure and support privacy by design. Aggregation reduces identification risk but does not automatically make data anonymous. Where re-identification remains reasonably possible, the data remains personal data and continues to be protected. Data is treated as anonymous only where it has been irreversibly de-identified.

Part III — Purposes of processing and legal bases

Article 5 — Purposes for which personal data is processed

Gratiago processes personal data only for defined purposes documented in the RoPA and assessed, where applicable, in the DPIA.

It processes data to create and manage accounts, authenticate users, manage access rights, maintain account security, enable account modification or deletion, and provide related support.

It processes data to operate the platform: recording user-entered information, storing adherence and medication data, displaying information, allowing users to review their entries over time, and supporting configuration and preferences.

Medication, adherence, questionnaire, side effect, note and other user-entered data are processed to allow users to record and review information within the platform. Where such data reveals or relates to health, it is treated as special category data under Article 9 GDPR.

Gratiago processes usage, interaction, behavioural, technical, access and security data to understand how the platform is used, maintain and improve functionality, identify technical issues, protect the platform, detect unauthorised access, investigate security events, prevent fraud, maintain audit logs and protect the confidentiality, integrity and availability of personal data.

Access for support or administration is restricted, logged and limited to authorised personnel under confidentiality obligations. Gratiago may also produce aggregated reports for service improvement, evaluation, internal reporting or governance, applying controls to prevent disclosure of identifiable information. It also processes data where necessary to comply with legal obligations and demonstrate GDPR accountability.

Article 6 — Legal bases for processing

Each processing activity is linked to an appropriate legal basis under Article 6 GDPR and, where special category data is processed, an applicable condition under Article 9 GDPR, as documented in the RoPA.

Performance of a contract (Article 6(1)(b)): where processing is necessary to provide the platform and requested services — account creation and management, authentication, access, core functionality, storage and display of user-entered data, account modification or deletion, and service-related support.

Explicit consent (Article 9(2)(a)): where users enter medication, adherence, questionnaire, side effect, note or other health-related data. Consent is obtained through a clear affirmative action and recorded so it can be demonstrated. It may be withdrawn at any time, without affecting prior lawful processing.

Legitimate interests (Article 6(1)(f)): for security monitoring, fraud prevention, access logging, system integrity, service improvement, behavioural analytics, performance monitoring, troubleshooting, governance and operational administration, where not overridden by the rights of the data subject. Users may object.

Legal obligation (Article 6(1)(c)): where processing is necessary to comply with Gratiago's legal obligations, respond to lawful requests, maintain required records and document GDPR compliance.

Part IV — Special category data, consent and user control

Article 7 — Processing of health data and other special category data

Gratiago processes data that may reveal information about a user's health, treatment, medication use, symptoms, side effects or adherence behaviour. Such data is treated as special category data under Article 9 GDPR, processed on the basis of the user's explicit consent (Article 9(2)(a)) and only for the purposes documented in the RoPA and DPIA.

Article 8 — Consent management

Where consent is relied upon, it is obtained before the relevant processing begins, through a clear affirmative action. Gratiago does not use pre-ticked boxes, implied consent or bundled consent. Consent is freely given, specific, informed, unambiguous, explicit for special category data, recorded as evidence and capable of being withdrawn. Consent records are maintained within the PIMS.

Article 9 — Withdrawal of consent

Users may withdraw consent at any time, without affecting the lawfulness of prior processing. On withdrawal, Gratiago ceases the dependent processing without undue delay, unless another legal basis applies or retention is legally required. Withdrawal may lead to deletion, restriction, anonymisation or disabling of certain functionality. Withdrawal is possible through the application where available, or by contacting privacy@gratiago.com.

Article 10 — User control over data entered in the platform

Users control the information they enter and are responsible for its accuracy and appropriateness. They should not enter data about other individuals unless necessary, appropriate and lawful. Where the platform allows, changes are reflected in the active environment, subject to technical constraints, audit logging, backup cycles and legal retention obligations.

Article 11 — Limits of consent and safeguards

Consent is not a general permission to process data for any purpose; it is limited to the specific purpose for which it was collected. Gratiago applies safeguards to protect sensitive data: purpose limitation, data minimisation, role-based access control, access logging, segregation where feasible, pseudonymisation, masking, tokenisation or aggregation, restrictions on administrative access, confidentiality obligations, processor controls, security monitoring and periodic review.

Part V — Recipients, processors and international transfers

Article 12 — Recipients of personal data

Gratiago does not sell personal data. Data is made available only where necessary for platform operation, security, administration, support, governance or compliance. Recipients may include the user (for their own data), healthcare professionals where the platform permits and access is lawfully configured, authorised Gratiago personnel or contractors, technical service providers acting as processors, professional advisers, and competent authorities where legally required. Access is limited to what is necessary and subject to appropriate controls.

Article 13 — Healthcare professionals and independent processing

Gratiago controls processing carried out within the platform environment. Healthcare professionals, institutions or other third parties may act as independent controllers for processing they carry out outside the platform. Gratiago is not responsible for such independent processing. Access by healthcare professionals within the platform is controlled through authentication, role-based permissions, user configuration and access logging.

Article 14 — Processors and sub-processors

Gratiago uses service providers to support operation, hosting, development, maintenance, security, administration, monitoring, communication, backup and support. Where they process data on Gratiago's behalf, they act as processors or sub-processors under Article 28 GDPR, only on documented instructions, and implement appropriate technical and organisational measures.

Article 15 — Key service providers

The platform uses third-party providers for core technical functionality, which may include Supabase (database hosting, authentication, storage, backend APIs, logging, infrastructure), Lovable (application development, deployment or frontend environment) and GitHub (source code management, version control and development governance). The role, scope and safeguards for each are documented in the PIMS.

Article 16 — International transfers

Some service providers may process data outside the European Economic Area. Where this occurs, Gratiago implements safeguards required under Chapter V GDPR: adequacy decisions, standard contractual clauses, transfer impact assessments where required, supplementary measures, contractual restrictions and security measures such as encryption and access control.

Article 17 — External reporting and aggregated outputs

Gratiago may generate aggregated outputs for analytics, service improvement or governance. Where shared externally, it applies controls to prevent disclosure of identifiable data: aggregation thresholds, suppression of small groups, field limitation, content review and re-identification risk assessment. Aggregated outputs are not automatically anonymous.

Part VI — Retention, deletion and anonymisation

Article 18 — Retention principles

Gratiago retains personal data only as long as necessary for the purposes for which it was collected. Retention periods and criteria are documented in the PIMS. Gratiago does not apply indefinite retention in the operational environment. The DPIA confirms data is retained only as long as necessary for service delivery, security and compliance.

Article 19 — Account data

Account and identification data are retained while the account remains active. On account deletion or a valid request, they are deleted, anonymised or restricted, unless limited retention is necessary for legal, security, accountability or dispute-handling purposes.

Article 20 — User-generated content and health-related data

User content and health-related data are retained while the account remains active and necessary to provide the requested functionality. On account deletion, valid erasure request or withdrawal of consent without another legal basis, such data is deleted, anonymised or restricted, subject to technical constraints and backup cycles.

Article 21 — Technical, security and usage data

Access logs, security logs, session metadata, device information, IP addresses, error logs and audit logs are retained for a limited period necessary to operate, secure, monitor, troubleshoot and improve the platform, and reviewed periodically to remain proportionate.

Article 22 — Data subject requests and breach records

Gratiago manages data subject requests and breach records through its PIMS. Records relating to access, rectification, erasure, restriction, portability, objection, consent withdrawal, complaints and incident handling are retained as accountability evidence, limited to what is necessary.

Article 23 — Deletion and disposal

At the end of the retention period or after a valid request, Gratiago disposes of data using an appropriate method: deletion from active systems, irreversible anonymisation, restriction, revocation of access or overwriting through backup cycles. Where data exists in backups, deletion may not be immediate and follows defined retention cycles.

Article 24 — Anonymisation, aggregation and residual risk

Gratiago may anonymise or aggregate data where justified. Anonymisation means irreversible de-identification; aggregation reduces risk without automatically making data anonymous. Pseudonymised, masked, tokenised or aggregated data remains subject to the GDPR where re-identification remains reasonably possible.

Article 25 — Periodic review of retention

Gratiago periodically reviews retention periods, deletion rules, anonymisation controls and backup practices through its PIMS, and takes corrective action where data is retained longer than necessary.

Part VII — Security, confidentiality and controls

Article 26 — Security principles

Gratiago implements technical and organisational measures to protect personal data against unauthorised access, unlawful processing, destruction, loss, alteration or disclosure. These are defined and reviewed through the PIMS, having regard to the nature, scope, context and purposes of processing, the sensitivity of the data and the risks identified in the DPIA.

Article 27 — Technical and organisational measures

Measures may include encryption in transit and at rest where supported, authentication controls, role-based and least-privilege access, access and audit logging, input validation, secure API access, configuration and secret management, backup and recovery controls, monitoring, technical separation of data domains where feasible, and pseudonymisation, masking, tokenisation or aggregation. Organisational measures include defined roles, confidentiality obligations, access approval and review, incident management, processor due diligence, data processing agreements and governance through the PIMS.

Article 28 — Access control and administrative access

Access is restricted to authorised users, authorised healthcare professionals where applicable, and authorised Gratiago personnel or providers with a legitimate, documented purpose. Administrative and support access is limited, controlled and logged. Access rights are reviewed periodically and on relevant changes.

Article 29 — Logging and monitoring

Gratiago maintains logs and monitoring records where necessary to operate, secure, troubleshoot and audit the platform, configured to support security and accountability while limiting unnecessary exposure of personal data.

Article 30 — Development, configuration and change control

Gratiago applies controls to reduce risks from development, configuration and deployment: version control, change tracking, review of changes affecting personal data, restricted production access, environment separation where feasible, controlled test data, secure handling of credentials and secrets, and PIMS updates where a change affects the RoPA, DPIA, processors, retention or legal basis.

Article 31 — Processor and infrastructure security

Gratiago assesses and documents processor-related risks through its PIMS and requires appropriate contractual, technical and organisational safeguards: processing on documented instructions, confidentiality, security measures, support for data subject rights and breach handling, sub-processing restrictions, and return or deletion of data at the end of services.

Article 32 — Personal data breach management

Gratiago manages breaches through its PIMS in line with the GDPR: identification, assessment, containment, remediation, risk assessment and notification decisions. Where a breach is likely to result in a risk to individuals' rights and freedoms, Gratiago notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours. Where the risk is high, it informs affected individuals, unless an exception applies.

Article 33 — Residual risk and continuous improvement

Gratiago recognises that no measure eliminates all risk. The DPIA identifies residual risks (access control, data linkage, development tooling, logging, configuration, backend access, monitoring, backup, and the combination of data over time), managed through documented safeguards, periodic review and corrective action.

Part VIII — Rights of data subjects

Article 34 — General rights

Users have the rights provided under Articles 12–23 GDPR: to be informed, access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, withdrawal of consent, rights relating to automated decision-making where applicable, and to lodge a complaint with a supervisory authority. Gratiago supports these rights through documented processes in its PIMS.

Article 35 — Right of access

Users may obtain confirmation of whether their data is processed and, where applicable, access to it and information about the processing (purposes, categories, recipients, retention, rights, source, automated decision-making). Gratiago may provide a copy of the data, subject to GDPR limits, the rights of others, security and identity verification.

Article 36 — Right to rectification

Users may request correction of inaccurate data and completion of incomplete data. Where the platform allows, they may correct it directly; otherwise the request may be submitted using the contact details in this policy.

Article 37 — Right to erasure

Users may request erasure where a GDPR ground applies (data no longer necessary, consent withdrawn without another basis, successful objection, unlawful processing, legal requirement). The right is not absolute: Gratiago may retain limited data where necessary for legal compliance, legal claims, security, accountability or dispute handling.

Article 38 — Right to restriction of processing

Users may request restriction in the circumstances provided by the GDPR (contested accuracy, unlawful processing with restriction preferred over erasure, data needed by the user for legal claims, or pending verification of an objection). Where restricted, Gratiago limits processing to storage or other permitted processing.

Article 39 — Right to data portability

Where processing is based on consent or contract and carried out by automated means, users may receive the data they provided in a structured, commonly used, machine-readable format and, where technically feasible, request its transmission to another controller. It does not apply to data outside the scope of the GDPR, internal compliance records, security logs or information affecting the rights of others.

Article 40 — Right to object

Users may object to processing based on legitimate interests. On a valid objection, Gratiago stops the processing unless it demonstrates compelling legitimate grounds overriding the user's interests, or processing is necessary for legal claims. Objection applies in particular to behavioural analytics and service improvement.

Article 41 — Right to withdraw consent

Where processing is based on consent, users may withdraw it at any time, without affecting prior lawful processing. Withdrawal may affect the availability of functionality that depends on it. Withdrawal requests are recorded and managed through the PIMS.

Article 42 — Rights relating to automated decision-making

Users have the right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, unless permitted by the GDPR. Gratiago does not carry out such solely automated decision-making. Analytics, structuring, visualisation or summaries support functionality and do not produce a significant automated decision about the user.

Article 43 — How to exercise rights

Users may exercise their rights by contacting privacy@gratiago.com. The request should identify the right exercised and provide sufficient information to identify the relevant account or processing. Gratiago may request additional information to verify identity. It responds without undue delay and within one month of receipt, extendable for complexity. Where it does not act, it informs the requester of the reasons and of the right to complain or seek a judicial remedy.

Article 44 — Request handling and accountability

Gratiago manages requests through its PIMS, recording for each the date of receipt, identity verification, right exercised, processing concerned, assessment, response and closure date. These records are retained as accountability evidence.

Part IX — Automated decision-making, profiling and analytics

Article 45 — Automated decision-making

Gratiago does not make decisions based solely on automated processing producing legal or similarly significant effects within the meaning of Article 22 GDPR. The platform supports recording, organisation, display, analysis and review of data without producing an automated decision about the user. Outputs support user review and do not replace the judgment of the user or healthcare professional.

Article 46 — Profiling and structured evaluation

Gratiago may process usage, adherence, questionnaire, note, health-related and technical data in a structured manner to identify usage patterns, organise information over time, display adherence history, present trends, support usability analysis and detect security or operational issues. It does not use such processing to make solely automated significant decisions.

Article 47 — Behavioural analytics

Gratiago may process behavioural and usage data for purposes documented in the RoPA: frequency of use, interaction patterns, feature usage, adherence-related interaction, technical usage and security-relevant activity. Where based on legitimate interests, safeguards apply (purpose limitation, access restriction, minimisation, aggregation, right to object). Where it reveals health information, it is treated as special category data.

Article 48 — Summaries, views and derived data

Gratiago may generate structured views, summaries, timelines or visualisations from user-entered data to help users review information. Where derived from personal data they are treated as personal data, and where they reveal health information, as special category data, with appropriate safeguards.

Article 49 — No replacement of clinical judgement

The Gratiago platform is not intended to replace medical advice, diagnosis, treatment decisions or clinical judgement. Users must consult a qualified healthcare professional for medical questions. Healthcare professionals remain responsible for their own professional judgement. Gratiago does not make clinical decisions on behalf of users or healthcare professionals.

Article 50 — Safeguards for analytics and derived processing

Gratiago applies safeguards to analytics, profiling, structured processing and derived data: documentation of purposes in the RoPA, risk assessment in the DPIA where applicable, data minimisation, purpose limitation, restricted and role-based access, logging, aggregation or pseudonymisation, review of outputs before external disclosure, suppression of small cohorts and periodic review through the PIMS.

Part X — Complaints, contact and changes

Article 51 — Contact for privacy matters

Questions, requests or concerns regarding the processing of personal data may be addressed to Gratiago SRL, Belgium. The Data Protection Officer is Miguel Azevedo, contactable at privacy@gratiago.com.

Article 52 — Complaints

Users have the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the GDPR. For Belgium, the competent authority is the Data Protection Authority / Autorité de Protection des Données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, Belgium — contact@apd-gba.be, dataprotectionauthority.be. Users may also contact Gratiago first at privacy@gratiago.com.

Article 53 — Changes to this privacy policy

Gratiago may update this Privacy Policy to reflect changes to the platform, processing activities, legal bases, categories of data, recipients or processors, international transfers, retention practices, security controls, applicable law, or the records maintained in its PIMS. Where a change is material, Gratiago informs users through an appropriate channel (email, in-app notice). Where required, it requests renewed or additional consent.

Article 54 — Language and interpretation

This Privacy Policy may be made available in more than one language. Where different versions are available, Gratiago identifies the version that prevails in the event of inconsistency. If none is expressly identified, the English version will be used for interpretation, unless applicable law requires otherwise.

Article 55 — Accountability

Gratiago maintains privacy and data protection records in its PIMS to demonstrate GDPR compliance: the RoPA, DPIA, consent records, data subject request records, breach records, processor and sub-processor records, retention and deletion records, access control records, risk assessments, security records and privacy review records. These are maintained as controlled evidence of Gratiago's privacy governance.

Gratiago

Gratiago is an information and behavioural support tool for treatment adherence. It does not constitute medical advice and does not replace consultation with a healthcare professional.

Contact
hello@gratiago.com
© 2026 Gratiago · BE 0779.594.123 · Brussels, Belgium
FAQ Terms of use Privacy policy