Politique de confidentialité
Dernière mise à jour : 26 mars 2025
La version contraignante de cette Politique de confidentialité est en anglais. En cas de conflit avec une traduction, la version anglaise prévaut.
Sleptly's mission is to help people improve their sleep and overall well-being through science-backed insights and AI-driven behaviour change. This Privacy Policy explains what information we collect through our website and service, how we use it, and what choices you have. By accessing or using our Service, you agree to the practices described in this Policy.
Table of Contents
- How we collect information
- What we do with the information we collect
- How and when we share your information
- How long we keep your information
- Your rights and choices
- Transferring your information
- Residents of the EEA, UK, and Switzerland
- Changes to this Policy
- Contact Us
1. How We Collect Information
The information we collect depends on how you interact with our Service and the choices you make. We collect information from different sources:
Information you provide directly
- Account information: Name, email address, and password when you register.
- Demographic data: Age, gender, and similar demographic details you provide during onboarding.
- Health and sleep data: Information about your sleep patterns, stress levels, sleep goals, habits, and wellbeing — collected through the onboarding quiz and ongoing reflections. This is sensitive personal data and is treated accordingly.
- Communications: Any messages you send us via support or contact forms.
Information collected automatically
- Log data: IP address, browser type, browser settings, and the date/time of your visits.
- Device information: Device type, operating system, and unique device identifiers.
- Usage data: Pages visited, features used, time spent on pages, and navigation patterns within the Service.
- Cookie data: We and our partners use cookies and similar technologies. For more details, see our Cookie Policy.
Information we infer
We may derive new insights from the data you provide — for example, identifying patterns in your sleep responses to generate a personalised CBT-I profile.
2. What We Do With the Information We Collect
We use your information to provide and improve your experience. Specifically:
- Service delivery: To provide personalised sleep insights, CBT-I-based recommendations, and account management.
- AI analysis: To process your responses and generate your personalised sleep profile and recommendations.
- Business operations: Billing, security, fraud prevention, and compliance with legal obligations.
- Product improvement: To improve our models, features, and the overall quality of the Service.
- Communications: To send you account-related notifications, updates, and (with your consent) marketing communications.
- Customer support: To respond to your enquiries and help resolve issues.
We process your health and sleep data on the legal basis of your explicit consent (GDPR Art. 9(2)(a)), which you provide when completing the onboarding quiz. You may withdraw this consent at any time by deleting your account.
3. How and When We Share Your Information
We do not sell your personal data. We may share your information only in the following limited circumstances:
- Service providers: Trusted third-party vendors who help us operate the Service (e.g., cloud hosting, email delivery, analytics). These parties are contractually bound to protect your data and may only use it for the purposes we specify.
- Payment processors: When you make a purchase, payment data is shared with our payment provider (e.g., Stripe) solely to process the transaction.
- Corporate transactions: Your information may be transferred as part of a merger, acquisition, or sale of assets, with reasonable notice to you.
- Legal compliance: We may disclose your information when required by law or to respond to valid legal process.
- Safety and security: To protect the rights, property, or safety of Sleptly, our users, or the public.
4. How Long We Keep Your Information
We keep your information only for as long as necessary to provide our Service, fulfil the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements.
When you delete your account, we will delete or anonymise your personal data within 30 days, unless we are required by law to retain it longer.
5. Your Rights and Choices
You have meaningful control over your information. Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request deletion of your account and personal data.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to our processing of your data for direct marketing at any time.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
6. Transferring Your Information
Your information may be stored and processed in countries within the European Economic Area (EEA) or in countries that the European Commission has determined provide an adequate level of protection.
Where we transfer data outside the EEA to service providers, we use appropriate legal safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your rights and protections travel with your data.
7. Residents of the EEA, UK, and Switzerland
If you are located in the EEA, UK, or Switzerland, your data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable local law. You have the following additional rights:
- Right to access, rectification, or erasure of your personal data.
- Right to data portability where processing is based on consent or a contract.
- Right to withdraw consent at any time for future processing.
- Right to object to or restrict processing under certain circumstances.
- Right to lodge a complaint with your national supervisory authority. In Sweden, this is the Integritetsskyddsmyndigheten (IMY). In other EU member states, please contact your local Data Protection Authority.
We rely on your explicit consent as the legal basis for processing special category data (sleep and health information) under GDPR Article 9(2)(a). For other data, we rely on the performance of a contract and our legitimate interests.
For GDPR-related enquiries, please contact us at [email protected].
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and update the "Last Updated" date. If changes are significant, we will notify you by email or via a prominent notice on the Service. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
9. Contact Us
If you have any questions or concerns about this Privacy Policy or about how we handle your data, please contact us at [email protected].