OURA HEALTH PRIVACY POLICY –  ONLINE STORE AND WEBSITE

Last update: May 23, 2018

1. ABOUT THIS POLICY

At Oura Health Oy (“Oura”), we take data protection seriously.

This Privacy Policy has been put together to provide our online visitors and shoppers (“Customers” or “ you”) with transparent information about the privacy of this site. This Privacy Policy aims to answer the following questions:

• What personal data we collect when you browse or make purchases on this site
• How we may use and share your personal data
• The use of cookies on this site
• Your legal rights and how to exercise them

Please note that this privacy policy only applies to the processing of personal data carried out by Oura as a data controller and only in the context of running this site and online store.

The payment process of our online store is provided by an external service provider Stripe. For more information on how your payment information is processed please see Stripe Privacy Policy.

For the data processed by our application (including measurement data), please see our Oura App privacy policy.

This Privacy Policy may be updated from time to time. We will not make substantial changes without prior notice. You can determine when this Privacy Policy was last revised by referring to the “LAST UPDATE” date at the top of this page.

2. OUR CONTACT INFORMATION

Oura Health Oy
Business ID: 25427764
Address: Elektroniikkatie 3 90590 Oulu Finland
E-mail address: support@ouraring.com
Website: https://ouraring.com
Data Protection Officer: Markku Koskela, dataprotection@ouraring.com

3. WHAT PERSONAL DATA DO WE PROCESS?

The data collected on this site can be categorized into two groups: Customer data and Analytics data.

Although we do not normally use Analytics data to identify individuals, sometimes individuals can be recognized from it, either alone or when combined or linked with Customer data. In such situations, Analytics data shall also be considered to be personal data under applicable laws and we will treat the combined data as personal data.

Please note that payment information is processed by a third party payment service provider.

Oura may collect and process the following Customer data:

• Your name and contact details
• Phone number
• E-mail address
• Possible communication with us
• Invoicing and billing information
• Possible claims or refunds
• Delivery information and delivery status
• Your purchases on this site (item and value)
• Chosen payment method
• Possible use of discount or campaign codes;
• Direct marketing opt-outs and opt-ins

Analytics data may include for example the following data:

• IP address
• Device type
• Operating system
• Firmware version of the ring
• Bluetooth ID of the ring
• Time of visit
• Browser type and version
• Language settings

4. DATA SOURCES

Your Customer data is primarily received directly from you in connection with your registration or in connection with completing a purchase in our online store. We may also receive data directly from you if you contact us with a question or complaint.

Analytics data is automatically collected when you visit the site. We may also track transactions data as well as details of your browsing patterns on the site.

5. PURPOSES AND LEGITIMATE GROUNDS FOR PROCESSING

Purposes of processing

Processing and delivering your orders
We process personal data in the first place to process, handle and send your orders and to facilitate your shopping.

Customer communication
We may process personal data for the purpose of communicating with Customers. If you contact our customer service, we will use the provided information to answer your questions and for solving any issues you may have.

Analytics and service improvements
We may process information regarding the use of our site to improve our service quality. This may involve the use of analytics or the assessment of any trends on our website and in our online store. When possible, we will do this using only aggregated, non-personally identifiable data.

Direct Marketing
With your consent we may send you marketing material, such as newsletters or offers.

Legal grounds for processing
We process personal data to perform our contractual obligations towards Customers or to facilitate their entry into a contract at their request. We also process certain information to comply with legal obligations, such as accounting legislation.

Furthermore, we process personal data to pursue our legitimate interest to run, maintain and develop our business, for analytics and trend detection, direct marketing and to create and maintain customer relationships. We may also process data for responding to consumer claims, cases regarding product warranty and similar situations. When choosing to use your data on the basis of our legitimate interests, we carefully weigh our own interests against your right to privacy.

6. COOKIES AND ANALYTICS

We use various technologies to collect and store Analytics data and other information when Customers use our site, including third party cookies.

Cookies are small text files sent and saved on your device that allows us to identify visitors of our websites and facilitate the use of our site and to create aggregate information of our visitors. This helps us to improve our service and better serve our Customers. The cookies will not harm your device or files. We use cookies to tailor our site and the information we provide in accordance with the individual interests of our Customers.

You may choose to set your web browser to refuse cookies, or to alert when cookies are being sent.

Please note that some parts of our site may not function properly if use of cookies is refused.

Web analytics services
We use Google AnalyticsIntercom and other similar web analytics services to compile Analytics Data and reports on visitor usage and to help us improve the Services. Please visit their privacy policies for more information.

7. DATA TRANSFERS TO COUNTRIES OUTSIDE EEA

Oura stores the Customers’ personal data primarily within the European Economic Area.

However, we have service providers in several geographical locations. As such, we or our service providers may transfer personal data to, or access it in, jurisdictions outside the European Economic Area or the Customer’s domicile.

We will take steps to ensure that the Customers’ personal data receives an adequate level of protection in the jurisdictions in which it is processed. We provide adequate protection for the transfers of personal data to countries outside of the European Economic Area through a series of agreements with our service providers based on the Standard Contractual Clauses or other similar arrangements.

8. SHARING YOUR PERSONAL DATA

We may share data with our group companies, subsidiaries and affiliates. Otherwise we do not share personal data with third parties outside of our organization unless one of the following circumstances applies:

It is necessary for the purposes set out in this Privacy Policy
To the extent that third parties need access to personal data to enable the offering of the online store, Oura has taken appropriate contractual and organisational measures to ensure that personal data are processed exclusively for the purposes specified in this Privacy Policy and in accordance with all applicable laws and regulations.

For legal reasons
We may share personal data with third parties outside Oura’s organization if we have a good-faith belief that access to and use of the personal data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, security or technical issues; and/or (iii) protect the interests or safety of Oura or our Customers in accordance with the law. Where possible, we will inform Customers about such transfer and processing.

To our authorized service providers
We may share personal data to authorized service providers who perform services for us (including data storage, sales, marketing and Customer support). Our agreements with our service providers include commitments that the service providers agree to limit their use of personal data and to comply with privacy and security standards at least as stringent as the terms of this Privacy Policy. Please bear in mind that if you provide personal data directly to a third party, such as through a link on our website, the processing is typically based on their policies and standards.

For other legitimate reasons
If Oura is involved in a merger, acquisition or asset sale, we may transfer personal data to the third party involved. However, we will continue to ensure the confidentiality of all personal data. We will give notice to all Customers concerned when the personal data are transferred or become subject to a different privacy policy as soon as reasonably possible.

With your explicit consent
We may share personal data with third parties outside Oura’s organization for other reasons than the ones mentioned before, when we have the Customer’s explicit consent to do so. You have the right to withdraw this consent at all times.

9. HOW LONG DO WE KEEP YOUR DATA?

Oura does not store personal data longer than is legally permitted and necessary for the purposes specified above. The storage period depends on the nature of the information and the purposes of processing. The maximum period may therefore vary per use.

Storage periods reflect the time frames we may need data for accounting, claims handling, internal reporting or reconciliation purposes.

10. YOUR RIGHTS

Right to access
You have the right to access your personal data processed by us. You may contact us and we will inform you what personal data we have collected and processed regarding you.

Right to withdraw consent
In case the processing is based on your consent, you may withdraw the consent at any time. Withdrawing a consent may lead to fewer possibilities to use our site and online store. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Right to correct
Customers have the right to have incorrect or incomplete personal data we have stored about the Customer corrected or completed. You can correct or update some of your personal data through your account.

Right to erasure
Customers may also ask us to erase the Customer’s personal data from our systems. We will comply with such request unless we have a legitimate ground to not delete the data.

Right to object
Customers may object to the processing of personal data if such data are processed for other purposes than purposes necessary for the provision of the site and online store to the Customer or for compliance with a legal obligation. In case we do not have legitimate grounds to continue processing such personal data, we shall no longer process the personal data after your objection.

Right to restriction of processing
Customers may request us to restrict processing of personal data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. This may however lead to fewer possibilities to use our site.

Right to data portability
Customers have the right to receive their personal data from us in a structured and commonly used format and to independently transmit those data to a third party.

How to use the rights
The above mentioned rights may be used by sending a letter or an e-mail to us on the addresses set out above, including the following information: the full name, company name, address, e-mail address and a phone number. We may request the provision of additional information necessary to confirm the identity of the Customer. We may reject requests that are unreasonably repetitive, excessive or manifestly unfounded.

11. DIRECT MARKETING

Notwithstanding any consent granted beforehand for the purposes of direct marketing, you have the right to prohibit us from using your personal data for direct marketing purposes by contacting us or by using the unsubscribe possibility offered in connection with our newsletter.

12. SAFEGUARDING YOUR DATA

We do our best to keep your data safe and secure. We use administrative, organizational, technical, and physical safeguards to protect the personal data we collect and process. Measures may include, for example, where appropriate, encryption, pseudonymization and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience and ability restore the data. We regularly test our systems, and other assets for security vulnerabilities.

Should despite of the security measures, a security breach occur that is likely to have negative effects to your privacy, we will inform you and relevant authorities as required by applicable data protection laws.

13. LODGING A COMPLAINT

In case you consider our processing of personal data to be inconsistent with the applicable data protection laws, a complaint may be lodged with the data protection supervisory authority.

National Winner Nordic Startup Awards 2017 Reddot Award 2018 Winner European Union - European Regional Development Fund leverage from the EU 2014-2020