‍Privacy Policy - Cephalgo Research App

1. Introduction

Cephalgo ("we," "our," or "us") operates the Cephalgo research application (the "App") as part of the OPADE research project. This Privacy Policy explains how we collect, use, and protect your personal information when you use our App and associated EEG hardware device.

IMPORTANT: This App is designed for research purposes and collects sensitive health information including EEG signals and mental health assessments. Please read this Privacy Policy carefully before using the App.

2. Data Controller

CEPHALGO
Société par actions simplifiée
8 Rue des Veaux, 67000 Strasbourg, France
Email: privacy@cephalgo.com

3. Information We Collect

3.1 Account Information

  • Name: Your full name for account creation
  • Email Address: For account verification and communication
  • Account Credentials: Username and encrypted password

3.2 Health and Biometric Data

  • EEG Signals: Brainwave data collected through our paired hardware device
  • Emotional State Data: Real-time emotion measurements and assessments
  • PHQ-9 Scores: Depression screening questionnaire responses
  • GAD-7 Scores: Generalized Anxiety Disorder assessment responses
  • Session Data: Timestamps, duration of measurements, and usage patterns

3.3 Technical Information

  • Device Information: Mobile device model, operating system, app version
  • Usage Data: App interaction patterns, feature usage, error logs
  • Hardware Data: EEG device connection status and performance metrics

3.4 Automatically Collected Data

  • App Analytics: Anonymized usage statistics for app improvement
  • Crash Reports: Technical data when the app experiences errors

4. Legal Basis for Processing

We process your personal data based on:

  • Consent: You provide explicit consent for research participation and health data processing
  • Legitimate Interests: App improvement, security, and technical support
  • Legal Obligations: Compliance with applicable research and data protection laws

5. How We Use Your Information

5.1 Research Purposes

  • Conduct scientific research on brain activity and mental health
  • Analyze correlations between EEG signals and emotional states
  • Develop and improve mental health assessment tools
  • Publish anonymized research findings in academic publications

5.2 App Functionality

  • Provide personalized measurement sessions
  • Track your progress over time
  • Ensure proper device connectivity and data synchronization
  • Deliver app updates and security improvements

5.3 Essential Communications

  • Send critical security and safety updates
  • Provide technical support when requested
  • Notify you of changes to this Privacy Policy

6. Data Sharing and Disclosure

6.1 Research Centers and Academic Institutions

  • Anonymized Data: We may share de-identified, aggregated data with research centers, universities, and academic institutions participating in the OPADE project
  • No Personal Identifiers: Shared research data will not include names, email addresses, or other directly identifying information
  • Research Collaboration: Data sharing supports scientific advancement and collaborative research efforts

6.2 Service Providers

  • Cloud Storage: Secure, encrypted cloud services for data storage
  • Analytics Providers: Anonymized usage analytics for app improvement
  • Technical Support: Third-party services for app maintenance and support

6.3 Legal Requirements

We may disclose your information if required by law, court order, or to protect our rights and safety.

6.4 We Will Never

  • Sell your personal data to third parties
  • Share identifiable health data without your explicit consent
  • Use your data for commercial advertising purposes

7. Data Security

We implement robust security measures to protect your information:

  • Encryption: All data is encrypted in transit and at rest using industry-standard AES-256 encryption
  • Secure Storage: Data stored on secure, compliant cloud infrastructure
  • Access Controls: Strict access limitations to authorized research personnel only
  • Regular Audits: Periodic security assessments and penetration testing
  • Device Security: Secure communication protocols with EEG hardware

8. Data Retention

  • Active Research Period: Data retained for the duration of the OPADE research project
  • Post-Research: Anonymized data may be retained indefinitely for future research
  • Account Data: Personal identifiers deleted within 30 days of account closure
  • Legal Requirements: Some data may be retained longer if required by applicable law

9. Your Rights (GDPR)

As a data subject, you have the following rights:

9.1 Access and Portability

  • Request a copy of your personal data
  • Receive your data in a portable format

9.2 Correction and Deletion

  • Correct inaccurate personal information
  • Request deletion of your personal data ("right to be forgotten")

9.3 Consent Management

  • Withdraw consent at any time
  • Object to certain types of data processing

9.4 Restriction and Objection

  • Restrict processing of your data
  • Object to data processing for specific purposes

To exercise your rights, contact us at privacy@cephalgo.com

10. Special Considerations for Health Data

10.1 Sensitive Data Warning

This App processes sensitive health information. Participation is voluntary and you may withdraw at any time.

10.2 Medical Disclaimer

This App is for research purposes only and does not provide medical diagnosis or treatment recommendations.

10.3 Age Restrictions

This App is only available to users 18 years of age or older.

11. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) for transfers outside the EU
  • Adequacy Decisions where applicable
  • Additional Safeguards as required by law

12. Third-Party Services

12. Third-Party Services

The App may integrate with:

  • Cloud Storage Providers: For secure data backup
  • Analytics Services: For app performance monitoring
  • Research Platforms: For collaborative research activities

All third-party services are carefully vetted for security and privacy compliance.

13. Data Breach Notification

In the event of a data breach affecting your personal information:

  • We will notify relevant authorities within 72 hours
  • You will be informed if there is a high risk to your rights and freedoms
  • We will provide clear information about the breach and our response

14. Children's Privacy

This App is not intended for children under 18. We do not knowingly collect personal information from minors. If we discover such collection, we will immediately delete the information.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will:

  • Notify you of material changes via email or app notification
  • Post the updated policy with a new effective date
  • Obtain new consent if required by law

16. Research Transparency

16.1 Research Oversight

This research is conducted under appropriate ethical oversight and institutional review.

16.2 Publication of Results

Research findings may be published in academic journals using only anonymized, aggregated data.

16.3 Withdrawal from Research

You may withdraw from the research study at any time by contacting us or deleting your account.

17. Contact Information

For questions about this Privacy Policy or your personal data:

Privacy Officer:
Email: privacy@cephalgo.com
Address: CEPHALGO, 8 Rue des Veaux, 67000 Strasbourg, France

Data Protection Authority:
If you have concerns about our data handling, you may contact the French Data Protection Authority (CNIL) at www.cnil.fr

18. Consent

By using the Cephalgo App, you acknowledge that you have read, understood, and agree to this Privacy Policy. You provide explicit consent for the collection and processing of your health data for research purposes as described in this policy.

For EEG Data Collection: I understand that this App will collect my brainwave data through an EEG device and I consent to this collection for research purposes.

For Mental Health Assessments: I understand that this App will collect my responses to mental health questionnaires (PHQ-9, GAD-7) and I consent to this collection for research purposes.

Last Updated: July 11, 2025
Version: 2.0