Privacy Policy
Last updated: June 19, 2026
This Privacy Policy describes Médecins Sans Frontières (MSF)'s policies and procedures regarding the collection, use, and disclosure of your information when you use the OpenTeleRehab service. It also explains your privacy rights and how applicable data protection laws protect you.
The English language version of this Privacy Policy shall prevail in the event of any inconsistency between translated versions.
We use your Personal Data to provide, maintain, and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
Interpretation and Definitions
Interpretation
Words with initial capital letters have meanings defined under the following conditions. These definitions apply whether they appear in singular or plural.
Definitions
For the purposes of this Privacy Policy:
Account means a unique account created for you to access our Service or parts of our Service.
Application means the software program provided by the Organization, downloaded by you on any electronic device, named OpenTeleRehab.
Organization (referred to as "MSF", "we", "us", or "our" in this Privacy Policy) refers to:
Médecins Sans Frontières – Operational Centre Brussels (MSF-OCB)
Rue de l'Arbre Bénit 46
1050 Brussels
Belgium
For the purposes of the General Data Protection Regulation (GDPR), MSF is the Data Controller.
Data Controller means the legal entity that determines the purposes and means of processing Personal Data.
Data Processor means any natural or legal person who processes Personal Data on behalf of MSF. This includes companies or individuals providing hosting, maintenance, technical support, analytics, or other services related to the operation of OpenTeleRehab.
Device means any device capable of accessing the Service, including computers, mobile phones, and tablets.
Personal Data means any information relating to an identified or identifiable natural person.
Service refers to the OpenTeleRehab application and its associated services.
Usage Data refers to information collected automatically through use of the Service or its supporting infrastructure.
You means the individual accessing or using the Service. Under the GDPR, you may also be referred to as the Data Subject.
Collecting and Using Your Personal Data
Types of Data Collected
Personally Identifiable Information
We may collect personal information necessary to provide healthcare services and operate the application. This may include:
- First name and last name
- Date of birth
- Gender
- Preferred language
- Country, region, or state
- Mobile phone number
- Text messages
- Images
- Video messages
- Usage Data
Sensitive Personal Information
Because OpenTeleRehab is a healthcare application, we process certain categories of sensitive personal data relating to your health.
This may include:
- Medical diagnosis
- Rehabilitation activity planning
- Treatment adherence information
- Clinical outcome measures
This information is processed only where necessary for the provision of healthcare services and in accordance with applicable data protection laws.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include:
- IP address
- Browser type and version
- Device identifiers
- Mobile device information
- Operating system
- Date and time of access
- Pages visited
- Time spent within the application
- Diagnostic information
When accessing the Service from a mobile device, additional technical information may be collected automatically.
Use of Your Personal Data
MSF may use your Personal Data for the following purposes:
To provide and maintain the Service
Including:
- Providing rehabilitation plans prescribed by your healthcare provider
- Monitoring adherence
- Allowing healthcare providers to review progress
- Delivering healthcare services through OpenTeleRehab
To manage your Account
To create, configure, and maintain your account and provide access to authorized features.
To communicate with you
Including:
- Audio or video consultations
- SMS
- Push notifications
- Security notifications
- Service updates
Research and service improvement
We may generate anonymized or aggregated statistical information to:
- Improve the Service
- Conduct research
- Evaluate application performance
- Improve user experience
No identifiable information is used for research unless permitted by law or with appropriate legal basis.
Sharing Your Personal Data
MSF may share your Personal Data in the following circumstances.
With Data Processors
We may share your information with trusted service providers who assist in:
- Hosting
- Infrastructure
- Maintenance
- Technical support
- Analytics
- Security monitoring
These providers process data only on behalf of MSF and under appropriate contractual safeguards.
With Your Healthcare Providers
To provide rehabilitation services, authorized healthcare professionals must be able to access your relevant medical information.
Your healthcare provider creates and manages your account and may access information necessary to provide your care.
Retention of Your Personal Data
MSF retains Personal Data only for as long as necessary to:
- Provide healthcare services
- Meet legal obligations
- Resolve disputes
- Enforce legal agreements
Usage Data is generally retained for shorter periods unless required for:
- Security
- Fraud prevention
- Legal compliance
- System improvement
International Transfers of Personal Data
Your Personal Data may be processed in countries other than your own where MSF or its service providers operate.
Whenever Personal Data is transferred internationally, MSF will ensure appropriate safeguards are implemented in accordance with the GDPR and applicable data protection legislation.
Disclosure of Personal Data
MSF may disclose Personal Data:
To comply with legal obligations
Including lawful requests from courts or government authorities.
To protect legitimate interests
Where necessary to:
- Protect the rights of MSF
- Protect patient safety
- Prevent fraud
- Investigate misuse of the Service
- Protect against legal liability
Security of Your Personal Data
MSF takes appropriate technical and organizational measures to protect Personal Data against:
- Unauthorized access
- Loss
- Destruction
- Disclosure
- Alteration
Although no electronic system can guarantee absolute security, we continuously work to maintain appropriate safeguards proportional to the risks involved.
Data Processors
MSF may engage third-party service providers for:
- Hosting
- Cloud infrastructure
- Technical maintenance
- Authentication
- Phone verification services
- Performance monitoring
These providers process Personal Data only under instructions from MSF and in accordance with applicable data protection laws.
GDPR Privacy
Legal Basis for Processing
MSF processes Personal Data under one or more of the following legal bases:
- Your consent
- Provision of healthcare services
- Compliance with legal obligations
- Protection of vital interests
- Legitimate interests where appropriate
Special categories of health data are processed in accordance with Article 9 of the GDPR.
Your Rights
Under the GDPR you have the right to:
- Access your Personal Data
- Correct inaccurate Personal Data
- Request deletion of Personal Data
- Receive a copy of your Personal Data
- Restrict processing
- Object to processing
- Withdraw consent where processing is based on consent
Please note that exercising certain rights may affect our ability to provide healthcare services through OpenTeleRehab.
Exercising Your Rights
You may exercise your GDPR rights by contacting MSF using the contact details provided below.
We may request proof of identity before responding to your request.
You also have the right to lodge a complaint with your local Data Protection Authority.
Links to Other Websites
The Service may contain links to third-party websites.
MSF is not responsible for the privacy practices or content of external websites.
We encourage you to review the privacy policies of any external websites you visit.
Changes to This Privacy Policy
MSF may update this Privacy Policy from time to time.
Where significant changes are made, we will notify users through the application or by other appropriate means and, where required by law, request renewed consent.
The updated version will always be available within the application.
Controller and Data Protection Officer
If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please contact:
Médecins Sans Frontières – Operational Centre Brussels (MSF-OCB)
Rue de l'Arbre Bénit 46
1050 Brussels
Belgium
Email: dpo@brussels.msf.org
This Privacy Policy is governed by the applicable data protection laws of the European Union and Belgium, including the General Data Protection Regulation (EU) 2016/679 (GDPR). Any disputes shall be subject to the jurisdiction of the competent courts of Belgium, unless otherwise required by applicable law.