Privacy Policy

Last updated: May 2026

Data Controller

JUVENO Care ApS (CVR 46292154, Denmark) is the controller for processing of personal data relating to medical assessment, treatment, and follow-up.

JUVENO Health BV (KVK 42040834, the Netherlands) is the controller for platform operations, subscription administration, and payment.

Contact: [email protected] (data protection), [email protected] (general).

Introduction

This policy describes how JUVENO collects, uses, and protects your personal data in accordance with the GDPR, the Danish Data Protection Act, and Danish health legislation, in particular the Danish Health Data Act (Sundhedsdataloven). We process health data, which is a special category under GDPR Article 9, and therefore apply heightened safeguards.

What we process

Standard personal data

  • Name, address, email, phone number
  • Account and login data
  • Payment data (via an external payment provider)
  • Correspondence in the patient portal

Health data (special category, Art. 9)

  • Answers to clinical questions (initial intake)
  • Hair loss pattern, medical history, current medication
  • Scalp images captured by the doctor during consultation
  • Clinical notes, diagnosis, treatment plan, prescriptions
  • Follow-up data (self-reports, follow-up images)

Identification data

  • Civil registration number (CPR), only used at MitID verification before prescription issuance, under § 11 of the Danish Data Protection Act
  • MitID verification receipt (proof of completed ID check)

Legal bases

  • Contract (GDPR Art. 6(1)(b)) - creating and operating your account and fulfilling the treatment subscription.
  • Processing of health data for healthcare purposes (GDPR Art. 9(2)(h)) - medical assessment, diagnosis, prescription, and follow-up. This is the primary legal basis for processing your health data.
  • Explicit consent (GDPR Art. 9(2)(a)) - only for processing that goes beyond healthcare purposes.
  • Legal obligation (GDPR Art. 6(1)(c)) - retention of clinical records under § 35 of the Danish Health Data Act (10 years from last entry).
  • Legitimate interest (GDPR Art. 6(1)(f)) - server logs and security monitoring.

CPR is also processed under § 11(2) of the Danish Data Protection Act, which permits use of CPR in the healthcare sector where needed for unambiguous identification.

Processing purposes

  • Patient account - identification, communication, record keeping.
  • Initial intake - the doctor's assessment of whether you are eligible for treatment.
  • Booking and video consultation - calendar coordination and video call via an EU-based video platform.
  • MitID identification before prescription - secure patient identification prior to prescription issuance.
  • Prescription issuance - creating and sending the prescription to the partner pharmacy.
  • Pharmacy order - transmitting the prescription and CPR to Glostrup Pharmacy for compounding and dispensing.
  • Treatment follow-up - self-reports, images, secure messaging via the patient portal.

Who receives your data

Your data is processed internally by JUVENO staff with a need to know. Doctors and clinical staff are bound by professional secrecy under § 40 of the Danish Health Act.

We use the following categories of data processors, all bound by data processing agreements and located in the EU/EEA:

  • Cloud hosting and application runtime (EU region)
  • Database hosting (EU region)
  • Transactional email (EU sending region)
  • Video consultation platform (EU)
  • MitID broker (EU-based)
  • Secure file storage for scalp images (EU region, encrypted with customer-managed keys)

The following are independent controllers, not processors:

  • Glostrup Pharmacy - medication handling under Danish pharmacy law, either on the basis of an authorisation (fuldmagt) or for treatment purposes.
  • Payment provider - independent controller for the payment transaction.

A specific list of our named processors is available on request from [email protected].

Transfers outside the EU/EEA

Your data is stored in the EU/EEA. Some of our processors have a US parent entity even though data is stored and processed in the EU. For those we rely on the EU Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework as the transfer basis.

Retention periods

  • Clinical data (journal, consultations, prescriptions, clinical images): 10 years from last entry, under § 35 of the Danish Health Data Act.
  • Account, login and communication: as long as you have an active account. Deleted 6 months after account closure, except for items covered by clinical retention duties.
  • Billing data: 5 years from end of the financial year, under § 12 of the Danish Bookkeeping Act.
  • MitID verification receipt: retained together with the corresponding prescription for the 10-year clinical period.
  • Cookie preferences: stored locally in your browser until you clear them.

Your rights

Under the GDPR you have the following rights:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17) - limited by clinical retention duties; does not apply to clinical records within the 10-year period.
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20) - you can receive your account and intake data in a structured format.
  • Objection (Art. 21) to processing based on legitimate interest.
  • Withdrawal of consent (Art. 7(3)) - does not affect the lawfulness of past processing, but may affect our ability to deliver the treatment.

Rights are exercised by emailing [email protected]. We respond within 30 days. For erasure requests about clinical data, we will explain what can and cannot be erased under healthcare retention duties.

Security

We have implemented technical and organisational measures to protect your data, including:

  • Encryption of health data and CPR numbers at rest, with customer-managed keys
  • Access control based on need to know
  • Encrypted connections (TLS) in transit
  • Audit logging of access to clinical data
  • Secure hosting in the EU
  • Professional secrecy for all clinical staff under § 40 of the Danish Health Act

Cookies

Our website only uses strictly necessary cookies:

  • Session cookie (login)
  • Beta-site protection
  • Eligibility-quiz state
  • Language preference
  • Cookie consent (stored locally in your browser)
  • Post-booking confirmation
  • MitID flow

We do not use tracking or marketing cookies. You can manage cookies via your browser settings.

Complaints

If you believe that our processing of your personal data is in breach of the GDPR, you may lodge a complaint with the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, [email protected], www.datatilsynet.dk.

Changes

We may update this policy. Material changes will be communicated via the platform or by email to registered users. The latest version is always available at juveno.health/privacy.

Contact

[email protected] (data protection and rights)

[email protected] (general)