Privacy Policy
Last updated October 2026
Introduction
Shifo (Insamlingsstiftelsen Shifo Foundation, org. no. 802477-8089, Hälsovägen 11C, 141 57 Huddinge, Stockholm, Sweden) ("Shifo", "we", "us") respects your privacy. This Privacy Policy explains what personal data we collect, why, how we protect it, and your rights whether you are a website visitor, donor, health worker, patient, employee or partner using our digital health platforms (including MyShifo, Clarity, CV2, and related services). By using our website or services, you acknowledge this Privacy Policy.
1. Who This Policy Applies To
- Website visitors and donors using www.shifo.org
- Health workers, facility staff and administrators using the MyShifo app, Clarity, CV2 and related Shifo digital health tools
- Patients and data subjects whose health data is collected through Shifo systems by health facilities and partner organisations.
2. Information We Collect
2.1 Website & Donor Information
- When you create a profile, donate, or contact us, we collect basic information such as your name and email address, and any additional information you choose to provide (e.g., photo, date of birth). If you register via Facebook, you grant Shifo permission to access your basic Facebook profile information in accordance with Facebook's terms and this Policy.
- We use Google Analytics to understand website usage (pages viewed, date/time, browser, approximate location via IP). This data is not linked to individual user profiles.
2.2 Health & Programme Data
Through our digital health platforms (MyShifo, Clarity, CV2, SPT forms, and related tools), Shifo processes health-related data on behalf of health facilities, ministries of health, and programme partners, including:
- Patient personal and identifying information (e.g., name, date of birth, national/patient ID, contact details)
- Patient health and healthcare-related information (e.g., diagnosis, treatment, service records, immunisation and facility-visit data)
- Health facility, service-delivery, and programme/operational data
For this data, Shifo acts as a data processor on behalf of the relevant health facility, ministry, or programme partner (the data controller), except where Shifo itself determines the purposes of processing, in which case
2.3 Mobile App Permissions (SMS/OTP)
The Shifo mobile application (MyShifo) requests the SEND_SMS permission, used exclusively to send a one-time password (OTP) directly from the health worker's device to patients for authentication and verification during registration workflows. The SMS is generated and sent locally from the device; Shifo does not intercept, store, or share the SMS content. This permission is never used for marketing or unrelated purposes. By using the app, you consent to this specific use.
2.4 Cookies
We use cookies to support website sessions and to understand site usage for performance improvement. No personally identifiable information is collected through cookies. You can control cookies through your browser settings.
3. How We Classify and Protect Data
Shifo classifies information as Confidential, Restricted, or Public according to its sensitivity, and applies protections accordingly. PII, and PHI are treated as Confidential and receive the highest level of protection, including:
- Encryption of confidential data at rest and in transit, using industry-standard algorithms (e.g., AES-256) and secure transport (TLS)
- Role-based access control, restricting access to those with a legitimate need, with multi-factor authentication for privileged access
- Regular vulnerability scanning and periodic penetration testing of our systems
- Logging and monitoring of access to production systems
- Documented incident response and business continuity/disaster recovery procedures, tested periodically
These measures are part of Shifo's information security management system, which is aligned with ISO/IEC 27001.
4. How We Use and Share Information
We use personal information only: (a) for the purpose for which it was collected, (b) in connection with services you opt into, and (c) in anonymised/aggregated form for reporting and improvement. Shifo does not sell, rent, or give away personal information. We share information only:
- With the health facility, ministry, or programme partner that is the data controller for the relevant health data
- With service providers who process data on our behalf under contract (e.g., cloud hosting, payment processing, analytics), each bound by confidentiality and security obligations.
- When required by law, regulation, or a valid legal request
5. International Data Transfers
Shifo operates across multiple countries.Data is processed and stored only within systems and environments approved for that purpose.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law or contractual obligation. Retention periods vary by data type and are set out in our internal Data Retention Matrix; for example, customer/programme data is generally deleted within 90 days of contract termination, unless a longer period is required by law. Patient data is retained according to the terms agreed with the relevant health facility or ministry, and is deleted or de-identified when no longer needed for a legitimate purpose.
7. Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we (or our partners, as controller) hold about you
- Request correction of inaccurate data
- Request deletion of your data, where applicable
- Object to or restrict certain processing
- Request a copy of your data in a portable format
- Lodge a complaint with a supervisory authority, such as the Swedish Authority for Privacy Protection (IMY)
For health data processed on behalf of a health facility or ministry (where Shifo acts as processor), requests should generally be directed to that organisation as the data controller; Shifo will support them in responding. For all other requests, contact us using the details in Section 11.
8. Children's Privacy
Our website and donation features are not directed at children. Individuals under 18 should have parental consent to donate or join the Shifo community; Shifo does not independently verify parental consent. Where Shifo systems process data relating to minors as patients (e.g., child immunisation records) on behalf of a health facility, this is done under the legal basis and safeguards established by that facility/programme, in compliance with applicable law.
9. Data Security Incidents
Shifo maintains a documented incident response process. In the event of a security incident affecting personal data, we will assess the incident, take appropriate containment and remediation steps, and notify affected data controllers, individuals, and/or regulators as required by applicable law and contractual commitments, without undue delay.
10. Links to Other Websites
Our website may link to third-party websites (e.g., PayPal). This Privacy Policy does not apply to those sites; please review their own privacy policies. See PayPal's privacy policy for details on how PayPal handles your information.
11. Contact Us
For questions about this Privacy Policy or to exercise your rights, contact us at: info@shifo.org
Visiting Address: Hälsovägen 11C, 141 57 Huddinge, Stockholm, Sweden
Postal Address: Ekshäradsgatan 89, 123 46 Stockholm, Sweden
Organisational no.: 802477-8089
12. Changes to This Policy
We may update this Privacy Policy from time to time.We encourage you to review this page periodically.