This Privacy Policy explains how we collect, use, and protect personal data when you use ViTA-related services available at:
https://www.aphasia-vita.com (website)
https://app.aphasia-vita.com (platform)
(together, “ViTA” or the “Platform”).
We are committed to protecting your personal data and ensuring transparency in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
2. DATA CONTROLLER AND EEA REPRESENTATIVE
Data Controller:
Harmonic Advance LLC
Address: Doroga Kryvchytska 17-a, Lviv, Ukraine
Email: team@aphasia-vita.com
EEA Representative (Article 27 GDPR):
Oksana Lyalka
Email: o.lyalka@aphasia-vita.com
In certain cases, therapists using the Platform may act as independent data controllers for patient data they manage. In such cases, ViTA acts as a data processor on their behalf.
3. WHAT DATA WE COLLECT
We collect personal data depending on how you interact with ViTA.
3.1 Website Data
When you visit https://www.aphasia-vita.com/, we may collect:
a) Technical data
- IP address
- Device and browser information
- Usage logs (for security and analytics)
b) Cookies and tracking data
- Necessary cookies
- Analytics data
- Preferences and settings
(see Section 11)
c) Contact and communication data
- Name
- Email address
- Messages and inquiry history
d) Information you provide voluntarily via contact form
- Role (therapist or patient)
- Name, email
- Information in free text window
3.1 Platform Data
a) Therapists
- Name and surname
- Email address
- Password (securely hashed)
- Professional activity (e.g. interventions created)
- Usage and interaction data
- Administrative and activity data (e.g. login status, actions performed within the Platform such as creating interventions or managing patients)
b) Patients (registered by therapists)
- Name and surname
- Email address
- Date of birth
- Gender
- City
- Language
- Diagnosis-related information (e.g. aphasia)
- Therapy responses and performance data
- Progress and interaction data
- Administrative and activity data related to their interaction with the Platform (e.g. login status)
This data may include health-related data, which is a special category of personal data under Article 9 GDPR.
c) Data provided directly by patients
- Login credentials
- Any data entered during use of the Platform
4. PURPOSES AND LEGAL BASIS FOR PROCESSING
Providing and operating the Platform
Art. 6(1)(b) GDPR
Managing user accounts and support
Art. 6(1)(b) GDPR
Improving and developing the Platform
Art. 6(1)(f) GDPR (legitimate interest)
Security, monitoring, and prevention of misuse or unauthorized access
Art. 6(1)(f) GDPR (legitimate interest)
Processing health-related data
Art. 9(2)(a) GDPR (explicit consent) and/or Art. 9(2)(h) GDPR
Communication with users
Art. 6(1)(b) or Art. 6(1)(f) GDPR
Marketing communications to therapists (email, only with prior consent)
Art. 6(1)(a) GDPR (consent)
Where required, explicit consent is obtained from the data subject or by the therapist/organization acting on their behalf.
5. HOW WE USE YOUR DATA
We use personal data to:
- Provide core functionality of ViTA
- Enable therapy-related features
- Maintain and improve performance
- Ensure security and prevent misuse
- Respond to inquiries and provide support
- Send service-related updates
- Send marketing communications (only with consent, where applicable)
- Administer and monitor the Platform, including reviewing user activity to ensure proper operation, security, and compliance
- Use anonymized data for research.
6. DATA SHARING
We do not sell personal data.
We may share data with:
- Service providers (processors)
(e.g. hosting, analytics, infrastructure, communication tools) - Authorities, where required by law
All processors are bound by Data Processing Agreements (DPAs) and comply with GDPR.
A list of key sub-processors is available upon request.
7. DATA RETENTION
We retain personal data only as long as necessary:
Data Category
Retention Period
Therapist account data
Duration of account
Patient account data
Duration of account
Consent records
Duration of processing + 3 years
When personal data is deleted, we may retain and continue to use data that has been irreversibly anonymized (i.e. cannot be linked to an identified or identifiable individual) for purposes such as research, statistical analysis, and improvement of the Platform.
You may request deletion of your personal data at any time, subject to applicable legal obligation, via email team@aphasia-vita.com.
8. DATA SECURITY
We implement appropriate technical and organizational measures:
- Secure data storage
- Access controls
- Encryption in transit and at rest (where appropriate)
- Restricted access to authorized personnel only
Special category data (including health data) is processed with additional safeguards and access restrictions.
9. INTERNATIONAL DATA TRANSFERS
Your data may be transferred outside the EEA, including to:
- Ukraine
- Third-party service providers
Ukraine is not currently recognized by the European Commission as providing an adequate level of data protection.
We ensure safeguards through:
- Standard Contractual Clauses (SCCs)
You may request a copy of these safeguards.
10. YOUR RIGHTS
Under GDPR, you have the right to:
- Access your data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time
To exercise your rights you may reach out to team@aphasia-vita.com.
You may also lodge a complaint with supervisory authority in your country of residence within the EEA.
11. COOKIES AND TRACKING TECHNOLOGIES
11.1 Types of Cookies
fStrictly necessary (no consent required)
- _cfuvid — security and traffic management
Analytics (consent required)
- _ga, _gaVNYJF4GZBG — Google Analytics
Consent management
- _OptanonConsent — stores cookie preferences
Application cookies
- ai_user — user recognition within the Platform
Debugging / performance cookies
- _ar-debug — system monitoring
11.2 Legal Basis
- Necessary cookies: Art. 6(1)(f) GDPR (legitimate interest)
- All others: Art. 6(1)(a) GDPR (consent)
11.3 Managing Cookies
You can manage cookies via:
- Cookie banner
- Browser settings
Disabling certain cookies may significantly affect the functionality.
11.4 Third-Party Providers
Cookies may be set by:
- Google (Google Analytics)
These providers process data under their own privacy policies.
12. CHILDREN’S PRIVACY
The Platform is not intended for direct use by children under 16 without parental or guardian consent.
Where a patient is under 16, the therapist is responsible for obtaining valid consent before entering data into the Platform.
13. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically.
For significant changes:
- We will notify users in advance (e.g. via email or Platform)
- Continued use after the effective date constitutes acceptance
14. CONTACT
Harmonic Advance LLC
Email: team@aphasia-vita.com
Address: Doroga Kryvchytska 17-a, Lviv, Ukraine