Privacy policy

BeSafePlus, BeSafeBasic & BeSafeNEXT

This shared privacy notice explains how personal data may be processed when the apps are used, and when one of the apps forms part of a research project at Aarhus University.

BeSafePlusBeSafeBasicBeSafeNEXT
Last updated: 23 September 2026
Important: This page supplements Aarhus University’s official privacy policy and any participant-information or consent material supplied for a specific research project. If study-specific information differs from this general page, the study-specific information takes precedence for that study.

1. Scope and data controller

This policy covers BeSafePlus, BeSafeBasic and BeSafeNEXT. The three apps may contain different modules or be configured differently in individual deployments. The exact processing therefore depends on the installed version, enabled functions and, where relevant, the research project in which the app is used.

When Aarhus University determines the purposes and means of processing personal data for its own activities, Aarhus University is the data controller. In some collaborations AU may instead act as a data processor on behalf of another controller; in that case the relevant controller’s information and data-processing agreement govern that processing.

BeSafeBasic

Covered by this shared notice. Only the data needed for enabled functions and the relevant study/deployment should be processed.

BeSafePlus

Covered by this shared notice. Device permissions and connected-device functions depend on the installed version and configuration.

BeSafeNEXT

Covered by this shared notice, including development and research deployments in which additional study modules may be enabled.

2. General GDPR principles

Personal data means information that can identify a person directly or indirectly. Depending on the app and research protocol, this can include ordinary personal data and special-category data such as health information.

The BeSafe apps are intended to follow the GDPR principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Personal data is not collected merely because it may be useful later.

  • No sale of personal data. Personal data is not sold to advertisers or data brokers.
  • No advertising profiling. Research or health-related information is not used to build advertising profiles.
  • Purpose-bound processing. Data is used for the app function, project administration, security, quality assurance and/or research purposes described to the user or participant.
  • Data minimisation. Only data reasonably necessary for the enabled purpose should be processed.

3. Privacy during use of the apps

3.1 Data that may be processed

Depending on the enabled functions, the apps may process one or more of the following categories:

  • participant, user or study identifiers; login/session identifiers; and, where applicable, contact details;
  • questionnaire answers, symptom reports, observations, measurements and other user-entered information;
  • health, wellbeing, activity or sensor/medical-device measurements when the relevant module is enabled;
  • technical information needed to operate and secure the service, such as app version, operating-system version, device model, timestamps, connection status, error/diagnostic logs and network/IP information;
  • research-derived or algorithm-derived variables created from collected data, where this is part of the relevant project.

The app may store some data temporarily on the device before secure transfer. Local storage should be limited to what is required for operation, offline use, reliability and error recovery.

3.2 Permissions on your phone or tablet

The permissions actually requested depend on the app version and enabled modules. The permission screen on your device is the most specific indication of what a particular installed version requests.

Permission / capabilityPossible purposePrivacy principle
Bluetooth / Nearby devicesConnecting to compatible measurement devices, gateways or sensors.Used only when a connected-device function is enabled.
LocationMay be required by some Android/OS versions for Bluetooth discovery, or by a specific research function.Not used for advertising or profiling. If actual location is collected for research, the purpose and whether foreground/background access is used must be stated separately to the participant.
Camera / QR scanningPairing, scanning a QR code, or entering a study/device identifier where enabled.Images are not retained unless the relevant function or study explicitly states otherwise.
NotificationsReminders, measurement prompts, study messages or operational alerts.Used for the enabled app/study function and can normally be managed in device settings.
Microphone, motion or activity sensorsOnly where a specific module or study requires these capabilities.The user/participant must receive an appropriate explanation before such data is used for research.
Internet / local networkSecure synchronisation, service communication, updates and connected-device communication.Communications should use appropriate encryption and access controls.

3.3 Security

AU’s privacy policy states that the university uses technical and organisational measures to protect personal data. For BeSafe deployments this should include measures appropriate to the risk, such as encrypted communication, access control, role-based access, secure authentication where required, logging, restricted administrative access, and pseudonymisation where feasible.

3.4 App stores and operating-system providers

Apple, Google and device/operating-system providers may process data independently in connection with app-store accounts, downloads, updates, crash services or operating-system functions. Their processing is governed by their own privacy terms. This shared BeSafe notice describes processing for which AU or the relevant research controller is responsible.

4. Privacy when the apps are used for research

Use of a BeSafe app in a study does not by itself constitute GDPR consent. The legal basis for a specific research project is decided by the data controller and must be stated in the study-specific participant information.

4.1 Sources of research data

Research data may be collected directly from you through the app, questionnaires, interviews, measurements or observations, and may in some studies be combined with information obtained from other lawful sources such as health systems, public registers, healthcare providers or collaborating institutions. Any such combination must be described in the relevant study information.

4.2 Legal basis used by AU for research

Aarhus University’s research-privacy information states that, depending on the project, ordinary personal data may be processed under GDPR Article 6(1)(e) (task in the public interest) or Article 6(1)(a) (consent). Sensitive personal data may be processed under Article 9(2)(j), together with section 10(1) of the Danish Data Protection Act and Article 6(1)(e), or under Article 9(2)(a) and Article 6(1)(a) when explicit consent is the chosen legal basis.

If a Danish civil registration number (CPR) is processed, AU states that this is done only when necessary for unique identification, in accordance with section 11(1) of the Danish Data Protection Act. Other sector-specific legislation, including health legislation, may also apply.

4.3 Pseudonymisation and access

Research data should be pseudonymised where this can be done without frustrating the research purpose. Access is limited to authorised persons with a need to know, and collaborators or service providers receive data only where there is a legal basis and appropriate agreements or safeguards.

4.4 Sharing and transfers

Research may involve collaboration across organisations or countries. If personal data is transferred outside the EU/EEA, AU states that an appropriate transfer basis and safeguards must be established so that protection is essentially equivalent to that required within the EU/EEA.

4.5 Retention

Data is kept only as long as needed for the stated purposes, subject to legal, documentation and research-integrity requirements. AU’s research notice states that research data, including personal data, is generally retained for at least five years after the latest research publication in order to document research integrity. Operational app data that is not required for research should be deleted, anonymised or archived when its purpose has been fulfilled, subject to applicable rules.

4.6 Withdrawal from a study and withdrawal of consent

If the processing is based on GDPR consent, consent may be withdrawn for future processing. Withdrawal does not make earlier lawful processing unlawful. Leaving a study does not necessarily mean that already collected research data must be erased; the applicable outcome depends on the study’s legal basis and research exemptions. The study-specific participant information should explain this.

5. Your data-protection rights

Under the GDPR, rights can include access, rectification, erasure, restriction, data portability in certain situations, objection, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

Research can involve statutory limitations or exemptions. AU’s general privacy policy notes that some rights may be limited in relation to research and public-authority tasks. AU’s research-privacy information further describes specific research limitations, including that erasure may be refused where deletion would make research impossible or seriously impair it. Study-specific information therefore matters.

Unless a specific study explicitly states otherwise, the BeSafe apps are not intended to make solely automated decisions that produce legal or similarly significant effects for the user. Algorithms may support monitoring, research analysis or alerts, but any materially different use must be described in the relevant project information.

6. Contact, DPO and complaints

Aarhus University

Nordre Ringgade 1
DK-8000 Aarhus C
Denmark

CVR no. 31119103
Phone: +45 8715 0000
Email: au@au.dk

For app- or study-specific questions, use the contact details shown in the app, study invitation or participant-information material.

AU Data Protection Officer

Aarhus University’s current privacy material identifies Niels Vase as Data Protection Officer.

Email: dpo@au.dk
Postal address: Aarhus University, Nordre Ringgade 1, DK-8000 Aarhus C, Attn.: Data Protection Officer.

Danish Data Protection Agency

You can complain about the processing of personal data to the Danish Data Protection Agency (Datatilsynet): Carl Jacobsens Vej 35, DK-2500 Valby, phone +45 33 19 32 00, dt@datatilsynet.dk. AU and Datatilsynet recommend that you normally contact the data controller first, so the issue can be assessed and, where possible, resolved.

7. Changes to this privacy policy

This page may be updated when app functionality, research use, suppliers or legal requirements change. The date at the top of the page shows the latest revision. Material changes affecting an ongoing study should also be communicated through the appropriate study/app channel where required.

8. Official AU and supervisory-authority information

This shared notice is designed to be read together with the current official material below:

This page summarises and supplements the official material; it is not a verbatim copy of AU’s privacy policy.