PRIVACY POLICY

Last updated
25.05.2026

1. INTRODUCTION

This Privacy Policy explains how we collect, use, and protect personal data when you use ViTA-related services available at:

https://www.aphasia-vita.com (website)

https://app.aphasia-vita.com (platform)

(together, “ViTA” or the “Platform”).

We are committed to protecting your personal data and ensuring transparency in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

2. DATA CONTROLLER AND EEA REPRESENTATIVE

Data Controller:
Harmonic Advance LLC
Address: Doroga Kryvchytska 17-a, Lviv, Ukraine
Email: team@aphasia-vita.com

EEA Representative (Article 27 GDPR):
Oksana Lyalka
Email: o.lyalka@aphasia-vita.com

In certain cases, therapists using the Platform may act as independent data controllers for patient data they manage. In such cases, ViTA acts as a data processor on their behalf.

3. WHAT DATA WE COLLECT

We collect personal data depending on how you interact with ViTA.

3.1 Website Data

When you visit https://www.aphasia-vita.com/, we may collect:

a) Technical data

  • IP address
  • Device and browser information
  • Usage logs (for security and analytics)

b) Cookies and tracking data

  • Necessary cookies
  • Analytics data
  • Preferences and settings

(see Section 11)

c) Contact and communication data

  • Name
  • Email address
  • Messages and inquiry history

d) Information you provide voluntarily via contact form

  • Role (therapist or patient)
  • Name, email
  • Information in free text window
3.1 Platform Data

a) Therapists

  • Name and surname
  • Email address
  • Password (securely hashed)
  • Professional activity (e.g. interventions created)
  • Usage and interaction data
  • Administrative and activity data (e.g. login status, actions performed within the Platform such as creating interventions or managing patients)

b) Patients (registered by therapists)

  • Name and surname
  • Email address
  • Date of birth
  • Gender
  • City
  • Language
  • Diagnosis-related information (e.g. aphasia)
  • Therapy responses and performance data
  • Progress and interaction data
  • Administrative and activity data related to their interaction with the Platform (e.g. login status)

This data may include health-related data, which is a special category of personal data under Article 9 GDPR.

c) Data provided directly by patients

  • Login credentials
  • Any data entered during use of the Platform

4. PURPOSES AND LEGAL BASIS FOR PROCESSING

Purpose
Legal Basis
Providing and operating the Platform
Art. 6(1)(b) GDPR
Managing user accounts and support
Art. 6(1)(b) GDPR
Improving and developing the Platform
Art. 6(1)(f) GDPR (legitimate interest)
Security, monitoring, and prevention of misuse or unauthorized access
Art. 6(1)(f) GDPR (legitimate interest)
Processing health-related data
Art. 9(2)(a) GDPR (explicit consent) and/or Art. 9(2)(h) GDPR
Communication with users
Art. 6(1)(b) or Art. 6(1)(f) GDPR
Marketing communications to therapists (email, only with prior consent)
Art. 6(1)(a) GDPR (consent)

Where required, explicit consent is obtained from the data subject or by the therapist/organization acting on their behalf.

5. HOW WE USE YOUR DATA

We use personal data to:

  • Provide core functionality of ViTA
  • Enable therapy-related features
  • Maintain and improve performance
  • Ensure security and prevent misuse
  • Respond to inquiries and provide support
  • Send service-related updates
  • Send marketing communications (only with consent, where applicable)
  • Administer and monitor the Platform, including reviewing user activity to ensure proper operation, security, and compliance
  • Use anonymized data for research.

6. DATA SHARING

We do not sell personal data.

We may share data with:

  • Service providers (processors)
    (e.g. hosting, analytics, infrastructure, communication tools)
  • Authorities, where required by law

All processors are bound by Data Processing Agreements (DPAs) and comply with GDPR.

A list of key sub-processors is available upon request.

7. DATA RETENTION

We retain personal data only as long as necessary:

Data Category
Retention Period
Therapist account data
Duration of account
Patient account data
Duration of account
Consent records
Duration of processing + 3 years


When personal data is deleted, we may retain and continue to use data that has been irreversibly anonymized (i.e. cannot be linked to an identified or identifiable individual) for purposes such as research, statistical analysis, and improvement of the Platform.

You may request deletion of your personal data at any time, subject to applicable legal obligation, via email team@aphasia-vita.com.

8. DATA SECURITY

We implement appropriate technical and organizational measures:

  • Secure data storage
  • Access controls
  • Encryption in transit and at rest (where appropriate)
  • Restricted access to authorized personnel only

Special category data (including health data) is processed with additional safeguards and access restrictions.

9. INTERNATIONAL DATA TRANSFERS

Your data may be transferred outside the EEA, including to:

  • Ukraine
  • Third-party service providers

Ukraine is not currently recognized by the European Commission as providing an adequate level of data protection.

We ensure safeguards through:

  • Standard Contractual Clauses (SCCs)

You may request a copy of these safeguards.

10. YOUR RIGHTS

Under GDPR, you have the right to:

  • Access your data
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent at any time

To exercise your rights you may reach out to team@aphasia-vita.com.

You may also lodge a complaint with supervisory authority in your country of residence within the EEA.

11. COOKIES AND TRACKING TECHNOLOGIES

11.1 Types of Cookies

fStrictly necessary (no consent required)

  • _cfuvid — security and traffic management

Analytics (consent required)

  • _ga, _gaVNYJF4GZBG — Google Analytics

Consent management

  • _OptanonConsent — stores cookie preferences

Application cookies

  • ai_user — user recognition within the Platform

Debugging / performance cookies

  • _ar-debug — system monitoring
11.2 Legal Basis
  • Necessary cookies: Art. 6(1)(f) GDPR (legitimate interest)
  • All others: Art. 6(1)(a) GDPR (consent)
11.3 Managing Cookies

You can manage cookies via:

  • Cookie banner
  • Browser settings

Disabling certain cookies may significantly affect the functionality.

11.4 Third-Party Providers

Cookies may be set by:

  • Google (Google Analytics)

These providers process data under their own privacy policies.

12. CHILDREN’S PRIVACY

The Platform is not intended for direct use by children under 16 without parental or guardian consent.

Where a patient is under 16, the therapist is responsible for obtaining valid consent before entering data into the Platform.

13. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically.

For significant changes:

  • We will notify users in advance (e.g. via email or Platform)
  • Continued use after the effective date constitutes acceptance

14. CONTACT

Harmonic Advance LLC

Email: team@aphasia-vita.com

Address: Doroga Kryvchytska 17-a, Lviv, Ukraine