Health Diary Application – Privacy Addendum

Version 1.0
Effective Date: November 27, 2025
Last Updated: November 27, 2025

Incorporation by Reference

This Diary Privacy Addendum supplements and incorporates by reference the Anspar Foundation General Privacy Policy (Version 1.0, Effective November 27, 2025). In the event of conflict between this Addendum and the General Privacy Policy, this Addendum controls for the Diary Application, except that this Addendum may not reduce the core protections established in Sections 6 (Your Rights), 7 (Data Security), and 14 (Complaints) of the General Privacy Policy.

Table of Contents

1. Application Overview

1.1 Application Description

The Health Diary ("Diary" or "Application") is a mobile and web-based health diary designed to help individuals track health observations and related information. The Diary serves multiple purposes:

1.2 Data Controllers

The following entities serve as Data Controllers for this Application:

Development Phase (Current):

Operational Phase:

1.3 Applicable Regulations

In addition to the regulations listed in the General Privacy Policy, when used for clinical trials, this Application is subject to:

1.4 Transferability

This Application is being developed by Anspar Foundation. The Application and associated data may transfer to the Sponsor Organization at a future date as determined by the contracting parties. Upon such transfer:

2. Data We Collect

This section details the specific data elements collected through the Health Diary.

2.1 Account and Identity Information

2.2 Health Data – Health Observations

For each health observation recorded:

2.3 Health Data – Additional Health Information

Users may optionally record:

2.4 Clinical Trial Data (When Applicable)

For users participating in clinical trials, additional data may include:

2.5 Technical and Device Data

2.6 Audit Trail Data (FDA 21 CFR Part 11 / EU Annex 11)

For regulatory compliance, the Diary maintains comprehensive audit trails including:

3. How We Use Your Data

3.1 Personal Health Management

3.2 Research (With Consent)

If you consent to contribute data for research:

3.3 Clinical Trial Support (With Consent)

For clinical trial participants who consent:

3.4 Diary Improvement

4. Data Sharing

4.1 Sponsor Organization (Opt-In)

We do not automatically share your data with the Sponsor Organization. If you choose to contribute your data to support research and patient services, you may opt in through the Diary's consent settings. Upon opting in, your data may be used for:

You may opt out at any time, which will stop future data sharing while preserving data already contributed to de-identified research databases.

Important: Under GDPR, you own your basic health data and may choose to share it with the Sponsor Organization independently of any clinical trial participation.

4.2 Clinical Trial Sponsors and Partners (Opt-In)

Clinical trial data sharing occurs only when you voluntarily enroll in a clinical trial and provide informed consent. If you choose to participate in a clinical trial, data may be shared with:

You will receive a separate, detailed informed consent document that explains exactly what data will be shared and with whom. You may decline trial participation without affecting your use of the Diary for personal health tracking.

Note on Third-Party Trial Participation: If you participate in other clinical trials or research studies, you may optionally indicate this participation (as a yes/no indicator only) to enable proper analysis of your data. No information about the identity of the sponsor, trial, or any other details will be collected or shared.

4.3 Healthcare Providers

At your direction, you may export or share your data with your healthcare providers.

4.4 Service Providers

We use the following categories of service providers, all bound by appropriate agreements:

5. Clinical Trial Provisions

IMPORTANT: This section applies only when you consent to participate in a clinical trial. Clinical trial requirements may override certain standard privacy provisions as permitted by law.

5.1 Regulatory Override

When you consent to participate in a clinical trial governed by FDA 21 CFR Part 11, EU Clinical Trial Regulation 536/2014, or ICH-GCP guidelines, the following regulatory requirements take precedence:

5.2 Patient-Reported Data Authority

Consistent with international consensus standards for clinical trials:

5.3 Modified Rights During Trial Participation

During active clinical trial participation, certain rights may be limited:

These limitations apply only to clinical trial data and only during the trial period plus required retention. Your non-trial personal health data remains subject to full privacy rights.

5.4 Electronic Signatures

For clinical trial data requiring electronic signatures (21 CFR Part 11):

6. Data Retention

6.1 Standard Retention (Non-Clinical Trial)

6.2 Clinical Trial Retention

Clinical trial data is subject to extended regulatory retention requirements:

The longest applicable retention period governs.

6.3 Deletion Requests

You may request deletion of your data subject to:

7. Local Data and Offline Operation

7.1 Offline-First Architecture

The Diary is designed to function offline:

7.2 Your Local Data

Data stored locally on your device:

7.3 Synchronization

When you choose to synchronize:

8. Your Rights

Your rights under the General Privacy Policy (Section 6) apply in full, with the following Diary-specific details:

8.1 Access and Export

8.2 Correction

8.3 Deletion

8.4 Consent Management

9. Contact Information

Diary-Specific Inquiries:
Email: privacy@anspar.org
Subject Line: Diary Privacy Inquiry

Development Phase Inquiries:
Anspar Foundation
Email: privacy@anspar.org

Clinical Trial Inquiries:
Contact your clinical trial site or the sponsor as identified in your informed consent form

General Privacy Inquiries:
See General Privacy Policy Section 13

Appendix A: Data Element Summary

The following table summarizes data elements, purposes, and legal bases:

Data Category Primary Purpose Legal Basis (GDPR) Retention
Account Info Service delivery Contract Account + 3 years
Health Observations Personal health tracking Explicit Consent Account + 7 years
Research Data Medical research Explicit Consent Indefinite (de-identified)
Clinical Trial Data Regulatory compliance Explicit Consent + Legal Obligation Up to 25 years
Technical Logs Operations/security Legitimate Interest 1 year
Audit Trails Regulatory compliance Legal Obligation Matches source data

Appendix B: Document Control

Version History:
Version 1.0 – November 27, 2025 – Initial Release

Related Documents:

Review Schedule:
This Addendum shall be reviewed at least annually and updated as necessary.

Approval:

___________________________________
Privacy Officer, Anspar Foundation
Date: _________________