MiMIAT Health Privacy Policy
Version 4
Effective date: 27 August 2026
MIMIAT HEALTH SL and the management of your personal data
At MIMIAT HEALTH SL, protecting the privacy and confidentiality of personal and health information is a fundamental part of how we provide MiMIAT Health.
This Privacy Policy explains what personal data we collect and process when you use the MiMIAT Health patient application and related patient-facing services, where that information comes from, why we process it, the legal bases we rely on, who may receive or process it, how long we retain it, and the rights available to you.
Health information is particularly sensitive. We therefore process health data only for specified purposes and in accordance with the safeguards and legal bases required under applicable data-protection law.
This Privacy Policy is a notice explaining how MiMIAT Health processes personal data. Acceptance of our Terms of Use does not, by itself, constitute consent to every processing activity described in this Privacy Policy.
Where applicable law requires your consent or explicit consent for a particular processing activity, MiMIAT Health will request that consent separately and in an appropriate manner.
If you have questions about this Privacy Policy, the processing of your personal data, or wish to exercise your data-protection rights, you may contact us at:
legal@mimiathealth.com
1. Who is responsible for processing your personal data?
The Data Controller is:
MIMIAT HEALTH SL
CIF: B19773761
C/La Rambla, 11, PRAL-1
08002 Barcelona, Spain
For privacy and data-protection matters:
legal@mimiathealth.com
For the purposes of this Privacy Policy, “MiMIAT Health”, “MiMIAT”, “we”, “us” and “our” refer to MIMIAT HEALTH SL.
This Privacy Policy applies to individuals using the MiMIAT Health patient application and related patient-facing services.
The MiMIAT Health patient Service is intended for individuals aged 18 years or older.
2. Data protection roles
The role of each party under data-protection law depends on the specific processing activity concerned.
MIMIAT HEALTH SL acts as Data Controller for processing activities for which it determines the purposes and essential means of processing, including the operation and provision of the MiMIAT Health patient Service directly to users.
Where technology or service providers process personal data on behalf of MiMIAT Health in order to provide infrastructure, storage, analytics, communications, security or other supporting services, they act as Data Processors where applicable and are subject to contractual and data-protection obligations appropriate to their role. Such providers may engage authorised sub-processors in accordance with applicable data-protection law.
Healthcare professionals and healthcare organisations that access information through MiMIAT Health for their own healthcare or professional purposes are not considered MiMIAT Health's Data Processors merely because they use the Service. Where they independently determine the purposes and means of their processing, including processing carried out for the provision of healthcare, they act as independent Data Controllers for that processing and are responsible for the legal and professional obligations applicable to them.
For certain institutional services or specific processing activities, MiMIAT Health may also act as a Data Processor on behalf of a healthcare organisation or other Data Controller. Where MiMIAT Health acts as a Data Processor, the relevant processing will be governed by an appropriate data-processing agreement in accordance with Article 28 GDPR.
Where two or more parties jointly determine the purposes and means of a specific processing activity, their respective roles and responsibilities will be determined in accordance with applicable data-protection law.
3. What personal data does MiMIAT Health process?
Depending on how you use MiMIAT Health and the functionality available to you, we may process the following categories of personal data.
Account and contact information
This may include:
preferred language;
email address;
first and last name;
telephone number;
account and authentication information; and
information necessary to create, secure and manage your MiMIAT Health account.
Profile and demographic information
This may include:
date of birth;
sex;
height;
weight;
selected health area or condition; and
other profile information you choose to provide.
Health and patient-reported information
MiMIAT Health allows you to record information relating to your health and clinical evolution.
Depending on the functionality available, this may include:
symptoms and symptom severity;
meals and dietary information;
bowel-movement information;
weight measurements;
treatments and medications;
health conditions;
lifestyle or health-related observations; and
other health information you choose to record.
Health information is treated as special-category personal data under the General Data Protection Regulation.
Certain account information is necessary to create and maintain a MiMIAT Health account. Most health information, clinical documents, images and connected-device information are provided at your choice.
Where particular information is necessary to provide a specific feature, we will indicate this when the information is requested. If required information is not provided, the relevant feature may not be available.
4. Clinical documents, files and images
Where this functionality is available, you may upload or capture files for inclusion in your MiMIAT Health record.
These may include, for example:
medical reports;
laboratory results;
prescriptions;
clinical letters;
diagnostic documentation;
images or photographs of clinical information; and
other documents relating to your health.
Files may contain personal data, health data and other sensitive information beyond the information visible in their title or file name.
MiMIAT Health processes these files in order to provide the functionality requested by you, including receiving, storing, retrieving, organising, presenting, sharing where authorised by you, and deleting files through the functionality made available by the Service.
Technical processing necessary to store, organise, transmit or present a document does not mean that MiMIAT Health independently changes the clinical meaning of the information contained within it.
5. Connected devices, wearable technologies and health platforms
Where you choose to connect a compatible device, wearable technology, operating-system health platform or third-party health service, MiMIAT Health may receive the information that the relevant source makes available under the permissions you grant.
Depending on the connected source and the functionality available, this may include information such as:
steps;
heart rate;
resting heart rate;
heart-rate variability;
activity or active time;
sleep duration and related sleep information;
weight; and
other compatible health or activity measurements.
We may also process information necessary to maintain the provenance and traceability of imported measurements, including:
the source platform, device or provider;
the date and time of a measurement;
measurement units;
connection identifiers; and
other technical source information necessary to identify where the measurement originated.
MiMIAT Health receives device information from the source selected by you. MiMIAT Health does not independently generate, alter or clinically reinterpret the underlying device measurement.
The availability and frequency of information may depend on your device, operating system, permissions, configuration, connectivity and the functionality made available by the relevant third-party provider.
You may revoke permissions or disconnect compatible services using the controls available through MiMIAT Health or the relevant third-party platform.
Disconnecting a source prevents MiMIAT Health from receiving new information from that connection once the disconnection takes effect.
Information already imported into your MiMIAT Health record remains subject to this Privacy Policy and the deletion and data-protection rights described below.
6. How do we obtain your personal data?
We obtain personal data from the following sources.
Directly from you
When you:
create your account;
complete your profile;
record health information;
upload documents or images;
communicate with MiMIAT Health;
request support; or
otherwise choose to provide information through the Service.
From services you choose to connect
When you choose to connect a compatible device, wearable technology, health platform or third-party service, we may receive information made available through that connection in accordance with the permissions you grant.
Through your use of the Service
We may process technical information necessary to operate, secure, maintain and troubleshoot the Service, such as:
IP address where processed by our infrastructure;
device and operating-system information;
timestamps;
application version;
authentication and security information; and
technical logs or error information.
App usage analytics
We may use analytics technologies, including Google Analytics, to understand how users interact with MiMIAT Health and to improve the design, functionality, reliability and performance of the Service.
Analytics information may include information such as:
application interactions;
session information;
screens or functionality used;
device and operating-system information; and
other technical usage information generated through interaction with the Service.
We configure analytics technologies in a manner intended to minimise the collection of directly identifying information where reasonably possible.
Where applicable law requires consent for the use of an analytics technology, we will request that consent before using the technology for that purpose.
MiMIAT Health does not use identifiable patient health information for third-party behavioural advertising.
We do not sell your personal data or health information.
7. For what purposes do we process your personal data?
We process personal data for the following purposes.
Providing and managing your account
To:
create and authenticate your account;
maintain your profile;
provide access to the Service;
communicate essential information relating to your account; and
manage account security.
Providing your longitudinal health record
To:
record health information you choose to provide;
organise and present your clinical evolution over time;
provide tracking and visualisation functionality;
store documents and information you choose to include in your record; and
provide other patient-facing functionality requested by you.
Connected-device functionality
Where you connect a compatible device or service, we process information received through that connection in order to import, organise and display it within your MiMIAT Health record.
Sharing authorised by you
We process information necessary to allow you to authorise healthcare professionals to access information from your MiMIAT Health record.
Maintaining and protecting the Service
We may process appropriate technical, account and security information to:
protect user accounts;
prevent unauthorised access;
detect technical or security incidents;
diagnose technical problems;
maintain the Service; and
improve its reliability and performance.
Usage analytics and service improvement
We may process analytics and technical usage information to understand how the Service is used and improve its usability, functionality and technical performance.
Support and communications
We process information you provide when you contact us in order to respond to your request and provide technical or general support.
Legal obligations
We may process information where necessary to comply with applicable legal, regulatory, judicial, security, accounting or other mandatory obligations.
8. What legal bases do we rely on?
Different legal bases may apply depending on the personal data and processing activity concerned.
Performance of our contract with you
Under Article 6(1)(b) GDPR, we process personal data where necessary to provide the Service requested by you, including creating and maintaining your account and providing MiMIAT Health's core functionality.
Explicit consent for health information
Health data is special-category personal data.
Where we process health information in connection with your MiMIAT Health record, including patient-reported health data, clinical documents, images and connected-device health information, we rely on your explicit consent under Article 9(2)(a) GDPR where this is the applicable condition for processing.
You may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Where processing of health information is necessary to provide a particular MiMIAT Health functionality requested by you, withdrawing consent may mean that we can no longer provide that functionality.
Sharing with healthcare professionals
Where you choose to share information from your MiMIAT Health record with a healthcare professional, we process the information necessary to carry out your instruction and rely on the applicable contractual and consent-based legal grounds, including explicit consent where required for the processing of health information.
Legitimate interests
Under Article 6(1)(f) GDPR, we may process appropriate non-health personal data where necessary for our legitimate interests in:
securing the Service;
preventing fraud or misuse;
troubleshooting;
protecting our systems;
providing support; and
improving the technical reliability and performance of MiMIAT Health.
Before relying on legitimate interests, we consider whether our interests are overridden by your rights and freedoms.
We do not rely on legitimate interest alone as the legal basis for processing special-category health information where an additional condition under Article 9 GDPR is required.
Analytics
Where analytics technologies require consent under applicable law, we rely on that consent.
Where consent is not legally required for a particular analytics or technical measurement activity, we may rely on our legitimate interest in understanding and improving the technical performance, reliability and usability of the Service, provided that this interest is not overridden by your rights and freedoms.
Legal obligations
Under Article 6(1)(c) GDPR, we may process personal data where necessary to comply with a legal obligation applicable to MiMIAT Health.
9. Who can receive or access your personal data?
We do not sell your personal data or health information.
Personal data is disclosed only where necessary for the purposes described in this Privacy Policy, where you direct us to share information, or where disclosure is required or permitted by law.
Healthcare professionals authorised by you
Where you authorise a healthcare professional to access your MiMIAT Health information, information made available through that connection may be accessed by that professional.
You may withdraw access using the controls available through MiMIAT Health.
Service providers acting on our behalf
MiMIAT Health uses specialist service providers to operate and protect the Service.
These may include providers of:
cloud infrastructure;
database and storage services;
analytics;
security and authentication;
notification and communication infrastructure;
technical monitoring and support; and
other technologies necessary to provide the Service.
Current service providers include services provided by:
Amazon Web Services (AWS)
MongoDB
Google, including Google Analytics where used
Vercel
Where these or other service providers process personal data on behalf of MiMIAT Health, they do so to the extent necessary to provide the relevant service and are subject to contractual and data-protection obligations appropriate to their role.
Professional advisers and public authorities
We may disclose personal data where necessary to:
comply with applicable law or binding legal process;
respond to competent regulatory, judicial or law-enforcement authorities;
establish, exercise or defend legal claims; or
obtain professional legal, accounting or auditing advice.
Corporate transactions
If MiMIAT Health undergoes a merger, acquisition, investment, restructuring or transfer of business assets, personal data may be disclosed where reasonably necessary for the transaction and subject to appropriate confidentiality and data-protection safeguards.
10. What role does a healthcare professional play?
Where you authorise a healthcare professional to access your MiMIAT Health record, MiMIAT Health provides the technical means through which the authorised information can be accessed.
The healthcare professional or healthcare organisation is responsible for its own use of personal data for the purposes of providing healthcare or other professional services in accordance with the legal and professional obligations applicable to it.
MiMIAT Health does not determine the healthcare professional's independent clinical decisions or professional purposes.
Depending on the context of a particular institutional deployment, MiMIAT Health may also process personal data on behalf of a healthcare organisation under a separate data-processing or data-governance agreement. Where this occurs, the respective responsibilities will be governed by the relevant agreement and applicable data-protection law.
11. Patient-controlled sharing
MiMIAT Health allows users to decide whether to authorise healthcare professionals to access information from their MiMIAT Health record.
Where supported by the Service, users may revoke a healthcare professional's access.
Revocation prevents that professional from continuing to access the user's MiMIAT Health record through the revoked MiMIAT Health connection.
Revoking access through MiMIAT Health does not erase personal data that a healthcare professional or healthcare organisation has lawfully received and is independently required or permitted to retain under healthcare, professional or other applicable law.
12. International data transfers
MiMIAT Health uses infrastructure designed to store core patient information within the European Union where configured for that purpose, including AWS infrastructure located in Ireland.
Some technology providers may nevertheless process or access limited personal data from countries outside the European Economic Area.
Where personal data is transferred to a country outside the EEA that has not been recognised by the European Commission as providing an adequate level of protection, MiMIAT Health uses an appropriate transfer mechanism required by applicable data-protection law.
This may include the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.
Information regarding applicable international-transfer safeguards may be requested by contacting:
legal@mimiathealth.com
13. How long do we retain your personal data?
We retain personal data only for as long as necessary for the purposes for which it is processed, taking into account the nature of the information, your use of the Service and applicable legal obligations.
Account and health-record information
While your MiMIAT Health account remains active, we retain the information necessary to provide your account and health record.
Account deletion
When you delete your account or successfully exercise a right requiring deletion, MiMIAT Health will initiate deletion of the relevant personal data from active systems, except where retention is necessary or permitted under applicable law.
Limited copies may remain temporarily in secure technical backups until those backups are overwritten or expire in accordance with applicable backup-management procedures.
Clinical documents, images and connected-device information
Clinical documents, images and information imported from connected devices or services that form part of your MiMIAT Health record are subject to the same deletion principles unless a different retention requirement applies and is communicated to you.
Legal, security and operational records
Certain limited information may be retained for longer where necessary to:
comply with legal obligations;
establish, exercise or defend legal claims;
prevent fraud or security abuse;
investigate security incidents; or
maintain evidence of legally relevant actions, instructions or consents.
When personal data is no longer required, it will be deleted or rendered anonymous in accordance with applicable requirements.
14. How does MiMIAT Health protect your personal data?
MiMIAT Health implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.
These measures include, as appropriate:
encryption of information in transit and at rest;
authentication and access controls;
restricted access based on operational need;
technical monitoring and security controls;
secure infrastructure and development practices; and
processes for responding to security incidents.
Access by MiMIAT Health personnel to personal or health information is restricted to authorised circumstances where such access is necessary for legitimate operational, technical-support, security or legal purposes.
We periodically review our technical and organisational safeguards as the Service and applicable risks evolve.
15. Your data-protection rights
Subject to the conditions provided by applicable law, you may have the following rights.
Access
You may request confirmation as to whether we process your personal data and obtain access to that information.
Rectification
You may request correction of inaccurate or incomplete personal data.
Erasure
You may request deletion of your personal data where the requirements for erasure under applicable law are met.
Restriction of processing
You may request restriction of processing in circumstances provided by law.
Objection
You may object to processing based on legitimate interests in circumstances provided by law.
Data portability
You may request eligible personal data in a structured, commonly used and machine-readable format and, where technically feasible, request that it be transmitted to another controller.
Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
To exercise your rights, contact:
legal@mimiathealth.com
We may need to verify your identity before completing a request in order to protect your information from unauthorised access or disclosure.
Where the GDPR applies, we will respond to requests to exercise data-protection rights within one month of receipt.
Where permitted by law, this period may be extended by up to two additional months where necessary, taking into account the complexity or number of requests.
If an extension is required, we will inform you within the initial one-month period and explain the reasons for the extension.
You also have the right to lodge a complaint with a competent data-protection supervisory authority.
In Spain, this includes the Agencia Española de Protección de Datos (AEPD).
16. Automated processing and clinical decisions
MiMIAT Health does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning users.
MiMIAT Health does not currently use automated processing to independently diagnose a disease, determine a treatment or replace the clinical judgement of a healthcare professional.
MiMIAT Health may use technical processing to organise, calculate or display information within the Service, including longitudinal visualisations and other non-decision-making functionality.
If MiMIAT Health introduces processing that falls within automated decision-making requirements under applicable law, this Privacy Policy and the relevant information provided to users will be updated accordingly.
17. Children's personal data
The MiMIAT Health patient Service is currently intended for users aged 18 years or older.
We do not knowingly offer the standard patient account-creation process directly to children.
If future functionality allows parents, guardians or other authorised persons to manage information concerning a child, that functionality will be subject to the appropriate legal basis, safeguards and privacy information before it is introduced.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
changes to MiMIAT Health functionality;
changes in the personal data we process;
new service providers or processing activities;
changes in applicable law or regulatory guidance; or
improvements to how we explain our privacy practices.
The current version and its effective date will be made available through MiMIAT Health and/or our website.
Where a change materially affects how we process personal data or the rights available to users, we will provide appropriate notice as required by applicable law.
Where a new or changed processing activity requires consent, we will request that consent separately.
19. Contact
For privacy, data-protection rights or questions regarding this Privacy Policy:
MIMIAT HEALTH SL
CIF: B19773761
C/La Rambla, 11, PRAL-1
08002 Barcelona, Spain
legal@mimiathealth.com
For general product or technical support:
support@mimiathealth.com