Privacy policy
The public part of Vårdbetyg, where you as a patient compare health centres, can be used entirely without an account: no tracking cookies, no profiling and no login are needed to read the site. Beyond that, a few optional parts let you choose to share information: a question about what you would like to know (only added to a total), a watch for one municipality (where you give your email address) and a contact form for care providers. There is also a separate, signed-in care-provider portal with personal, invitation-based accounts. None of these are needed to use the public comparison service. Here we describe clearly which data each part processes and why.
Data about you as a visitor
You never need to give us any information about yourself to read the public site, you need no account and do not log in, and we build no profile of you. The public forms are the search fields, which store nothing, the watch form on the municipality pages, where you choose to give us your email address, and the contact form for care providers (see their own sections below). The signed-in care-provider portal is described in the section The care-provider portal and accounts. We use no cookies for tracking or analytics and share no visitor data with ad networks.
If you answer the question What would you most like to know in the box What we cannot measure, we store only that one of the three ready-made options was chosen, together with page type, month, language and, on clinic and kommun pages, which kommun the page concerned. The kommun can never point to a clinic or a person. We store no IP address, no identifier and no link to the clinic you were looking at. Your answer is added to a total, so there is no row about you to retrieve. That you have already answered is remembered by your own browser, not by us.
Clinics that have earned a distinction can embed a seal image from us on their own website. When such an image is fetched we count the fetch in an aggregate per clinic, day and embedding website (the site’s address, never the page). We store no IP address, no cookie and nothing about you as a visitor – the count describes websites, not people.
If you click through from a clinic page – to register, call, open the map or read more on 1177 – the link goes via us before sending you on. We then add one to an aggregate per clinic, target and day: registering is counted on its own, apart from the information clicks. We store no IP address, no cookie, no timestamp and nothing about you: we can see that five people clicked on a given day, never who, and never that the same person also did something else here. We measure it to know whether the comparisons actually help anyone choose.
In the same way we count aggregates per clinic for how clinic pages are used: how many viewed a page on a given day, opened a section, shared the page, saved it for comparison, clicked the phone number, picked it in the site search or answered yes or no on whether a section helped (the answer is about our text, never about the care). When two clinics appear in the same AI comparison we also count the pair as a daily aggregate; it describes clinics, never you. Each event adds one to a daily bucket per clinic and nothing more: no IP address, no cookie, no timestamp and no link between two events. Clinics that sign in to our portal see their own aggregates, never anything about an individual visitor, and the numbers never affect ratings or rankings.
Inside the signed-in portal a clinic can save its own improvement actions: an action or check they want to carry out, a responsible role or function, their own follow-up measure, a follow-up date and a status, together with a copy of the open data shown when the action was created. The purpose is to offer the clinic this improvement feature. The texts are written by the clinic itself and are shown only inside the signed-in portal, to authorised sign-ins for the same clinic. They are never used for public ranking or for our AI analysis, and a clinic can delete its saved actions from the portal. Do not enter any patient data in the fields.
A clinic can attach a few summarised measures to an improvement action to follow it over time: a measure name and definition, a baseline and dated data points, an own target and a follow-up decision. The feature is built for aggregated figures at unit level, such as a proportion or a monthly value for the whole clinic. The clinic is responsible for entering only such aggregated values and never data about an individual patient. Points are entered by hand or imported as a file. On import the file is read, checked against the format and reasonable ranges, and then discarded; only the stored values are kept. Such a check catches obvious mistakes but cannot on its own guarantee that a small number does not happen to concern an individual, so the responsibility for keeping the figures sufficiently aggregated rests with the clinic. The measures and their values are shown only in the signed-in portal, are never used for public ranking or AI analysis, and are removed when the action is removed.
To understand whether the portal is actually used for improvement work we count a few content-free steps: that a page was viewed, a brief opened, an action saved, a data point added and a follow-up done. Each such event carries only which step it was, a timestamp and a de-identified, coded clinic id. It never contains action text, measure names, values, an email address, IP address or details about your browser, and is never sent to any other service.
To know what is worth building we count page views with Cloudflare Web Analytics. That measurement is cookieless and builds no profile: it sets no cookie, does no fingerprinting and does not follow you between visits or across websites. What is counted is aggregate, such as how many people visited a page and which referrer they arrived from. It is also why this site has no cookie banner. A small script is loaded from Cloudflare on every page; if you want to block it, an ordinary script or content blocker is enough, and the site works exactly as usual without it.
We also count page views ourselves, as an aggregate per type of page and day (for example the start page, a municipality page or the comparison), together with whether the page was the first one you saw here or was reached from another page on this site. Your browser decides that from whether you arrived from elsewhere, and the only things sent are which page it was and a yes or no. No address of the page you came from, no IP address, no cookie, no timestamp and nothing linking two page views. We do this to keep counting when the Cloudflare script is blocked, and to keep figures that Cloudflare only retains for six months.
As with every website, our hosting provider (Google Cloud / Firebase App Hosting) handles technical server logs – such as IP address and time – in order to run and protect the service. These logs are not used to profile individual visitors and are stored only for a limited time according to the provider’s routines. When we look at the logs ourselves to understand which pages are used, we only do so in aggregate, never to follow an individual visitor.
The care-provider portal and accounts
Health centres can be given access to a signed-in care-provider portal. Accounts are personal and created by invitation only: we invite a known contact person, and the account is activated through a time-limited link. For a portal account we process your email address (which is also the login identity), which health centre the account belongs to, and a password stored only as a cryptographic hash (never in clear text). The login itself is carried by a signed session cookie that contains only the email address, the chosen unit and an expiry time. We keep no separate session list, no IP address, no information about your browser and no special role beyond the link to the unit. Access is further limited to an approved list of units.
All business data in the portal (improvement actions, measures and data points as above) is tied to the health centre, not to an individual, and a login for one unit can never reach another unit's data. We deliberately do not store the creator's name or address on an action. The text fields are for the clinic's own improvement work. Never write patient data, personal identity numbers or other sensitive personal data in them.
The legal basis for the portal account and the unit-linked business data is our legitimate interest in providing and securing the service, and, where a customer agreement exists, the contract. When portal access or a customer relationship ends, we delete or anonymise the person-linked portal data (in practice the account email) at the latest twelve months after the end, except what must be kept due to law or a concrete legal claim. This is a manual routine: we review and remove the data, it does not happen automatically.
Contact form for care providers
The care-provider page has a contact form for product and contact enquiries, for example about a seal, a report or something else. If you send an enquiry we store what you fill in: your email address, your name if you give it, which health centre or organisation it concerns if you give it, the interest you chose and an optional message. We use the data to answer and administer your enquiry. A copy is sent to us through our email provider (Resend) so that we can reply. The form is protected against bots with Cloudflare Turnstile, which checks your IP address with Cloudflare at submission. We store no IP address in the enquiry itself.
Never write patient data or other sensitive personal data in the message field. The legal basis is our legitimate interest in answering and administering an incoming enquiry. If the enquiry does not become an active customer relationship, we delete or anonymise it at the latest twelve months after the last substantive contact, as a manual routine. Any accounting records that arise if you become a customer are covered by separate, statutory retention and are not mixed with this data. To have your enquiry disclosed, corrected or deleted, or to object to the processing, email us (see Your rights).
Our legitimate-interest assessment
For contact enquiries and for the portal accounts we rely on legitimate interest. In brief:
- Purpose: to answer and administer enquiries from care providers, and to provide and secure the care-provider portal.
- Necessity: we need an email address to reply and to let you log in, and the link to the right health centre to show the right data. We collect no more than that.
- Which data: limited, work-related data, an email address in the service, a name and an organisation if you give them, and for the portal a password hash. No sensitive personal data and no profiling.
- Reasonable expectations: you contact us or log in as a representative of an organisation, and it is expected that we process the data for exactly that purpose.
- Safeguards: data minimisation (we store no IP address, browser information or role), passwords only as a hash, a signed session cookie with an expiry, business data separated per unit, portal and contact data never reaching the AI feature, and the service running within the EU (Google Cloud, europe-west4).
- Right to object: you can object at any time to processing based on legitimate interest, see Your rights.
The map and your location
The Near me feature and the map ask your browser for your location only when you press the button yourself. The position is used solely to calculate distances and centre the map, directly in your browser – it is never sent to us or anyone else.
The map imagery is fetched as a static file from our own storage with the same hosting provider as the rest of the site (Google Cloud), not from any external map service. The map sets no cookies and shares nothing with third parties; the fetches are covered by the same technical server logs described above.
Data about health centres
The scores and statistics shown are aggregated, public data from the National Patient Survey – compiled answers at unit level, not data about individual patients or named staff. We fetch the data from the open results portal and process it according to the method we describe openly. Read more on About the data and Methodology.
If we sell statistics
Vårdbetyg may sell compiled statistics and reports to care providers and other organisations, for example comparisons of how health centres develop over time. The line is simple: what we sell is aggregated statistics, essentially from the same open sources the site is built on. We never sell personal data, and never anything at unit level derived from visitor data – what you do on the site can never become a sold figure about an individual health centre. Nor can money ever affect scores, rankings or selection; read more under Independence and funding.
Watching a municipality
If you sign up to watch a municipality we store your email address, the name of the municipality and the language you used. We first send an email asking you to confirm that the address is yours. If you do not confirm, the address is never used for anything. We use it only to tell you when we have added new figures for that municipality. We do not sell it, do not share it and send nothing else.
Every email has an unsubscribe link, and we use no tracking pixels, so we do not know whether you opened it. Once you unsubscribe the address stops being used, and it cannot be signed up again through the form, so nobody else can put you back on the list. If you would rather be removed from the list entirely than unsubscribed, get in touch at hej@vardbetyg.se and we will erase the record. The basis for the processing is your consent, and you can withdraw it whenever you like.
We also count how many people watch each municipality. That count is an aggregate with no link to your address; we use it to see where interest is growing, and if we ever show it publicly we do so only once the subscribers are numerous enough that no individual can be singled out. If we want to ask a voluntary follow-up question, for example whether you actually switched health centre, it is sent only to those who first said yes to exactly that in a separate choice. Not answering means no, and the watch continues as usual.
Your rights
The personal data we may hold about you is: an email address if you signed up for a municipality watch, the data in a contact enquiry if you sent one (email, name, organisation, chosen interest and message), and a portal account if you are a care provider (email, linked unit and a password hash). If you have only read the public site there is normally nothing to request, correct or erase; the technical server logs and the cookie-free visitor measurement cannot be looked up per person. You have the right to request, correct or erase the data we hold about you, and to object to processing based on legitimate interest (contact enquiry and portal account). The unsubscribe link in the watch emails stops the emails. To exercise a right, or if you have questions about privacy, email hej@vardbetyg.se and we will help you. You always have the right to turn to the Swedish Authority for Privacy Protection (IMY) with a complaint.
Changes
We update this page before any new feature that processes personal data goes live, and when an existing feature changes. This version describes the municipality watch, the contact form for care providers and the signed-in care-provider portal.