This policy describes how Risin Health collects, uses and protects the personal data of visitors to risinhealth.app. It applies only to this institutional site, patient data processed by healthcare facilities through Risin Hospital or LIA is governed by a separate data processing agreement.
1. Data controller
The data controller for this site is Risin Health SAS, a company under Ivorian law, headquartered in Abidjan, Côte d’Ivoire.
For any privacy-related enquiry: dpo@risinhealth.app.
2. Data we collect
This site is deliberately lean. The data we collect through risinhealth.app is limited to:
- Strictly necessary cookies (cookie banner state, preferred language).
- Anonymised audience measurement cookies (Google Analytics 4), only if you have opted in.
- Information you provide via the Calendly scheduling form (email, name, facility, chosen slot).
- Connection logs (IP address, User-Agent, timestamp) kept for 30 days for security purposes.
3. Legal basis
The processing described above relies on:
- Legitimate interest (security, fraud prevention) for connection logs.
- Consent (Art. 6.1.a GDPR) for non-essential cookies and Calendly scheduling.
- Performance of a contract (Art. 6.1.b) when you contact us for a commercial project.
4. Sub-processors and recipients
Data collected on this site is processed by:
- Cloudflare, hosting and database, GDPR + SCCs.
- Calendly (demo scheduling), Privacy Shield certified, US-EU transfer framed.
- Google Analytics 4 (anonymised audience measurement), IP anonymised, no sharing with other Google services.
5. Retention periods
Cookies expire after 12 months maximum; consent state is kept for 12 months.
Connection logs are kept for 30 days.
Calendly scheduling information is retained by Calendly under their own policy (24 months by default).
6. Your rights
Under GDPR and Ivorian law n°2013-450 on the protection of personal data, you have the following rights:
- Right of access to your data.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to restriction of processing.
- Right to data portability of data you provided to us.
- Right to object to processing on grounds relating to your particular situation.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Exercising your rights
To exercise any of these rights, write to dpo@risinhealth.app enclosing a proof of identity.
We commit to reply within 30 days.
Filing a complaint
If, after contacting us, you believe your rights have not been respected, you may lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with ARTCI (Côte d’Ivoire).
7. Security
We implement appropriate technical and organisational measures to protect your data: HTTPS encryption (TLS 1.3), strict security headers, hashed admin passwords, Secure cookies.
8. Changes
This policy may be updated to reflect changes to the service or the regulation. The last updated date is shown at the top of this page.