Version 3 - May 12, 2026 1:19 PM

Privacy Policy

Data controller and contact information

Hemi Klinik ApS
Peter Bangs Vej 7a
2000 Frederiksberg
Contact: hello@hemihealth.com

At Hemi, we are dedicated to protecting the personal data you provide to us. In this privacy policy, you can read about what information we collect, what we use it for, how we protect it, and what rights you have regarding our processing of your data.

In which situations do we collect and process your personal data?

  • When you book an appointment with us.
  • When you register as a user and use our mobile application.
  • When we need to prepare and carry out your treatment, either in person or online.
  • When we need to share your treatment plan with your doctor.
  • When we need to report to your insurance company.
  • When we need to disclose information to municipalities.
  • When we use AI-based tools as part of your treatment.
  • When we need to process your payment.
  • When you sign up for our newsletter.
  • When we contact you regarding relevant research projects.
  • When we need to respond to your general inquiries via, for example, email, social media, etc.

When you visit our website and cookies are placed on your device.

What personal data do we collect, for what purposes, and on what legal basis?

When booking an appointment with us, we collect general personal data such as your name, email, phone number, time of treatment, and your civil registration number (CPR number). Booking takes place either via our website, through our mobile app, or by calling our support staff.

The legal basis for processing general personal data is GDPR Article 6(1)(b), while the legal basis for processing your civil registration number (CPR number) is Section 12(1) of the Executive Order on Medical Records, which requires that the medical records we are obligated to maintain include your CPR number.

When creating a user account and using our mobile application, we collect general personal data such as your name, email, gender, date of birth, and phone number. This information is collected so that we can identify you in connection with treatments and so that you can log in again if, for example, you forget your password. The legal basis for processing this general personal data is your consent, cf. GDPR Article 6(1)(a).

We also collect sensitive personal data in the form of health information in the mobile application. We do this to enable you to use our migraine diary, and the legal basis for processing this health information is therefore also your consent, cf. GDPR Article 9(2)(a).

You can withdraw your consent at any time by writing to hello@hemihealth.com.

When preparing and conducting your treatment, whether in person or online, we process the personal data necessary to provide you with the best possible care. This includes general personal data such as your name, email, phone number, gender, date of birth, and other general personal data that may be relevant to the treatment. We only ask for information that is relevant to your treatment plan, and our staff is also subject to a statutory duty of confidentiality under Section 40(1) of the Danish Health Act. The legal basis for processing this general personal data is GDPR Article 6(1)(b).

In addition to general personal data, we also collect health information, such as the types of medication you use, the duration of conditions, types of headaches, etc. Our practitioners use the information you have registered in our mobile application, which includes general health information, specific migraine information, and data you have entered into the migraine diary if you have used it. This information is used collectively to analyze your condition so that a more accurate diagnosis can be made and the most effective treatment form can be recommended. The legal basis for processing health information for treatment purposes is GDPR Article 9(2)(h) regarding medical diagnosis and treatment.

During treatment, your civil registration number (CPR number) is also recorded to maintain medical records in accordance with legislation. The legal basis for this is Section 11(2)(4) of the Danish Data Protection Act, cf. GDPR Article 9(2)(h), and Section 12(1) of the Executive Order on Medical Records.

Your civil registration number (CPR number) is recorded in your medical file along with your health information and other details, as we are required to do so under Section 5 of the Executive Order on Medical Records.

When sharing a treatment plan with your doctor, general personal data such as your name, phone number, email, and civil registration number (CPR number), as well as sensitive personal data in the form of health information, are disclosed to your general practitioner. This occurs either by you sharing the information in your migraine diary via our mobile application or by you providing consent pursuant to GDPR Article 6(1)(a) and 9(2)(a) for Hemi to share information with your doctor. The purpose of this sharing is to provide your doctor with insights that can assist in more accurate diagnosis and, consequently, more effective treatment.

You can withdraw your consent at any time by writing to hello@hemihealth.com.

When preparing and disclosing reports to your insurance company, we process general personal data such as your name and contact details, as well as sensitive personal data in the form of health information and general details about your treatment plan. This information is used to prepare a report that can form the basis for the insurance company's handling of your case, including the assessment of treatment plans, coverage, and potential reimbursement, and in some cases, to initiate or follow up on a treatment plan.

As part of the report preparation, we use an AI-based tool that assists in structuring and generating the report based on the information we have registered about you. We have implemented technical measures to ensure that your personal data is anonymized/pseudonymized before we use the AI solution, so that in almost all cases, it is not shared with the provider of the solution.

The completed report is subsequently forwarded to your insurance company. The legal basis for this disclosure is your consent, pursuant to Section 41(1) of the Danish Health Act and Article 6(1)(a) and 9(2)(a) of the GDPR.

You can withdraw your consent at any time by writing to hello@hemihealth.com.  

When disclosing information to municipalities, we process and disclose general personal data such as name and contact details, as well as sensitive personal data in the form of health information and details about your treatment course.

Disclosure only occurs at your request or when you have provided consent, and the purpose is to support your case with the municipality, for example in connection with sickness benefits, resource programs, or other social services.

The legal basis for the processing and disclosure is your consent, cf. Section 41(1) of the Danish Health Act and GDPR Article 6(1)(a) and 9(2)(a).

You can withdraw your consent at any time by writing to hello@hemihealth.com.

When using AI-based tools as part of your treatment, we process the personal data necessary to support and streamline our healthcare work. This may include general personal data such as name and contact details, as well as sensitive personal data in the form of health information and details about your treatment course.

The information is used, for example, to assist our practitioners with record-keeping, structuring information and tasks, and drafting treatment notes, so we can ensure more efficient and consistent treatment.

Processing takes place as part of providing healthcare services. The legal basis for processing general personal data is GDPR Article 6(1)(b), while the legal basis for processing health information is GDPR Article 9(2)(h) regarding medical diagnosis and treatment. AI-based tools are used solely as an internal aid in the clinic and only after a thorough risk assessment and the implementation of appropriate technical and organizational security measures, ensuring your information is handled confidentially and securely.

When administering your payment, we process your general personal data such as name, address, phone number, and payment details. This information is processed and recorded so that we can receive your payment and comply with our documentation obligations under the Danish Bookkeeping Act. The legal basis for processing is therefore GDPR Article 6(1)(b) and Section 12(1) of the Danish Bookkeeping Act.

When you sign up for our newsletter, we collect your email address. We do this to send you messages about news, webinars, tips, and similar content. If you sign up for our newsletter in connection with booking an appointment, your email is collected based on your consent, cf. GDPR Article 6(1)(a). If you sign up via the front page of our website, the legal basis for processing is GDPR Article 6(1)(f).

You can withdraw your consent at any time either via the link in each newsletter or by writing to hello@hemihealth.com.

When contacting you regarding relevant research projects, we process your general personal data as well as sensitive personal data in the form of health information to assess whether you might be a candidate for a specific research project and to contact you about it.

The processing involves us screening your information to identify potential matches for relevant studies.

We screen your information and will only contact you if you have provided prior consent. The legal basis for this processing is your consent, cf. GDPR Article 6(1)(a) and 9(2)(a).

You can withdraw your consent at any time either via the link in each newsletter or by writing to hello@hemihealth.com.

For general inquiries, such as via email, social media, and similar channels, we typically collect your email address, name, the content of the inquiry, and other details provided. This information is necessary for us to respond to your inquiry, and as we have a legitimate interest in doing so, the processing is based on GDPR Article 6(1)(f). If you send us health information related to, for example, your treatment, the information is processed under GDPR Article 9(2)(h).

When you visit our website and mobile application, we use cookies to collect information such as your IP address, browser type, operating system, and pages visited on our website. We use this information to analyze and improve our website and mobile application, and analytical/marketing cookies are only placed and used for analysis/marketing if you provide your consent. You can read more about our collection of cookies further down on this page.

You can withdraw your consent at any time. Regarding cookies on the website, you can do this by scrolling down to our cookie policy and clicking on the text "Change your consent." Regarding cookies in the mobile application, please contact hello@hemihealth.com.

Which third parties do we share information with?

We use external third parties to provide a range of IT systems, such as our email system, electronic health record system, booking system, billing system, and website hosting. Additionally, we use various suppliers to provide services that enable us to operate and develop the applications we make available to both you and our employees. As part of this, we use, among others, hosting providers, services for sending SMS and emails, online consultations, and MitID login.

As mentioned, we may also disclose information to other healthcare professionals, such as general practitioners, if necessary for a current course of treatment.

A number of the third parties we use act as data processors in accordance with GDPR Art. 4(8). We have therefore entered into data processing agreements with them, thereby ensuring that your personal data is processed securely, properly, and in accordance with the law.

We are very mindful that the processing of personal data should, as far as possible, take place within the borders of the EU/EEA. In the event that a data processor transfers your personal data to a third country, appropriate safeguards are in place to ensure the protection of your information. These safeguards typically consist of the data processor having committed to complying with the EU’s Standard Contractual Clauses, cf. GDPR Art. 46(2)(c). Alternatively, transfers will be made to companies that are considered secure by the European Commission, cf. GDPR Art. 45.

How long do we store the information?

We generally ensure that your information is deleted when we no longer have a purpose for storing it.

Pursuant to Section 35(2) of the Executive Order on Medical Records, we are required to store patient records for at least 5 years after the most recent entry. Thereafter, they will generally be deleted, but there may be cases where storage for a longer period is necessary, for example, if a complaint or compensation case arises. If this occurs, the information will be deleted after the conclusion of the case or when the statute of limitations has expired in accordance with the Danish Statute of Limitations Act, cf. Section 35(5) of the Executive Order on Medical Records.

Information related to our customer relationship is deleted after the current year + 5 years, as storage for this period is required under Section 12(1) of the Danish Bookkeeping Act.

Job application data, such as CVs, educational information, applications, etc., are stored for up to 3 years after the recruitment process has concluded.

Information collected via cookies when you visit our website is stored for the period specified in our cookie policy, which you can view below. Documentation of your consent, if applicable, is stored for up to 2 years after your consent was given.

If you have signed up for our newsletter, we will store your name and email address until you unsubscribe.

You have the right to:

  • To gain access to the personal data Hemi processes about you.
  • To request the erasure of the personal data Hemi processes about you.
  • To demand rectification of the personal data Hemi processes about you.
  • To object to Hemi’s processing of your personal data.
  • To request the restriction of the processing of your personal data.
  • To receive your personal data in a structured, commonly used, and machine-readable format.

Please note that your right to erasure may be limited by our obligations under the Executive Order on Medical Records. Pursuant to this, we are unable to delete information in medical records, but can only make corrections.

Right to lodge a complaint

You may lodge a complaint with the Danish Data Protection Agency regarding Hemi’s processing of your personal data. Their contact details are:

Address: Carl Jacobsens Vej 35, 2500 Copenhagen
Email: dt@datatilsynet.dk
Phone: +45 33193200