Skip to content
Legal · Privacy

Privacy & GDPR.

How Supar Health collects, processes, stores, and protects your personal and health data. We treat your information with the rigour a clinical platform demands.

Effective17 May 2026
Last reviewed17 May 2026
Data controllerSupar Health ApS · Copenhagen

01Who we are

Supar Health ApS (referred to as "we", "us", "Supar Health") is a Danish-registered company headquartered in Copenhagen, Denmark. We are the data controller for the personal data processed through the Supar Health platform.

If you have any questions about this Privacy Policy or how we process your data, please contact our Data Protection Officer at [email protected].

02The data we collect

We collect the minimum personal data needed to provide the Supar® test and the Health Trajectory Report. The categories of data we process include:

  • Account information. Name, email address, password (hashed), phone number, billing address.
  • Health information. Date of birth, sex assigned at birth, suPAR test results, any clinical context you choose to provide, and the interpretation provided by the partner clinician.
  • Laboratory data. Sample identifiers, intake metadata, and laboratory results linked to your test.
  • Payment information. Processed by our payment provider; Supar Health does not store full card details.
  • Technical data. IP address, browser type, device information, cookie identifiers, and aggregated platform analytics.

03How we use your data

We process your personal data only for the following purposes:

  • To deliver the suPAR test you have ordered and to return the result and interpretation to you
  • To support clinical interpretation by the qualified clinician interpreting your result
  • To maintain your secure dashboard, including longitudinal tracking across repeat tests
  • To process payment and to comply with accounting and tax obligations
  • To communicate with you about your account, your test, or material changes to the platform
  • To improve the platform through aggregated, de-identified analytics
  • To meet our regulatory obligations under European data protection and clinical regulations

04Legal basis for processing

We process your personal data under one or more of the following lawful bases (GDPR Art. 6 and Art. 9):

  • Performance of a contract - to deliver the test and report you have ordered
  • Explicit consent - for the processing of health data (GDPR Art. 9(2)(a))
  • Legitimate interests - for improving platform security, fraud prevention, and aggregated analytics, where these do not override your rights
  • Legal obligations - for accounting, tax, and regulatory record-keeping requirements

05Sharing your data

We do not sell your personal data. We share data only as required to deliver the service or as required by law:

  • Partner clinicians and partner clinics involved in interpreting your result
  • Our laboratory, which processes your sample under strict confidentiality
  • Service providers such as payment processors, infrastructure providers, and email delivery - all bound by data processing agreements compliant with GDPR
  • Regulatory authorities, where we are legally required to disclose data

All third parties processing data on our behalf operate under data processing agreements that meet GDPR requirements and the EU Standard Contractual Clauses where applicable.

06Data retention

We retain your data only as long as is necessary for the purposes for which it was collected:

  • Active account data is retained while your account is active and for a reasonable period thereafter to support re-engagement and longitudinal tracking
  • Test results and clinical records are retained for the period required by applicable healthcare record retention laws
  • Financial records are retained for the period required by Danish accounting law (typically five years)
  • Marketing and analytics data are retained for shorter periods and may be anonymised earlier

You may request deletion of your data at any time, subject to legal retention obligations.

07Your rights under GDPR

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data, subject to legal exceptions
  • Restrict or object to certain processing
  • Receive your data in a portable format
  • Withdraw consent at any time for processing based on consent
  • Lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or the supervisory authority in your country of residence

To exercise any of these rights, contact [email protected].

08Security

We apply technical and organisational measures appropriate to the sensitivity of health data, including encryption in transit and at rest, access controls, audit logging, and regular security reviews. Our infrastructure is hosted in the EU.

09International transfers

Your data is processed within the European Union and the European Economic Area. Where any service provider operates outside the EEA, we use the Standard Contractual Clauses approved by the European Commission to ensure your data continues to receive equivalent protection.

10Cookies and analytics

We use a minimal set of cookies for essential platform function and aggregated, privacy-respecting analytics. We do not use third-party advertising trackers. A detailed cookie disclosure is available on request.

11Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active users by email. The current version is dated at the top of this page.

12Contact

Questions or requests regarding your personal data: [email protected].