Version 1.2 — 22 September 2026
MyClusters B.V. (MyClusters) is a digital platform for people living with cluster headaches (one of the most severe forms of headache known). Through our website and app, you can track your attacks, log symptoms and medication, gain personal insights, and choose to contribute to medical research. We also work with researchers and industry partners including pharmaceutical companies, medtech and neurotech firms, and medical supplies companies, who may access pseudonymised data from consenting users via our platform. Further contact details can be found at the bottom of this privacy statement.
Because you are a patient, the information you share with us is sensitive. We handle it with care, and this statement explains exactly what we collect, why, and what your rights are, in plain language.
A few things worth knowing from the outset:
We are committed to processing your personal data lawfully, transparently, and with the care that you may expect from a health-related platform.
When you visit our website, certain technical data are automatically collected to help us understand how the site is used and to improve its performance and user experience. Our service providers (i.e. (sub)processors) may also have access to your personal data, in 4. Safeguards you can find out more about them and what they process.
| Element | Details |
|---|---|
| Data processed | Browser type, browser behaviour (pages visited, session duration) |
| Purpose | Analytics and website improvement. The website can use cookies for this purpose. Find out more about the use and the retention period in our Cookie policy. |
| Legal basis | Consent for non-essential analytics cookies; Legitimate interest* for strictly necessary technical processing. |
| Tools used | Google Analytics, Umami, Squarespace Analytics. See 5. Sub-processors for details. |
| International transfer | Google Analytics: Data are transferred to the United States, EU–U.S. Data Privacy Framework applies. Squarespace: Data are transferred to the United States, SCCs apply. |
| Retention | Google analytics: Data are retained on Google's servers for 2 months, after which they are automatically deleted. Squarespace: Data are retained for the duration of our Squarespace account. Upon termination of the account, analytics data are deleted in accordance with Squarespace's policies. |
*Where we rely on legitimate interest as our legal basis, we have weighed our interests against yours and concluded that our interests are not overridden by your rights or freedoms. This balancing assessment has been documented and is available on request.
Our website embeds videos hosted on YouTube (operated by Google LLC). When you interact with an embedded video, or, depending on cookie settings, when the page loads, Google may place cookies on your device and collect data about your viewing behaviour.
| Element | Details |
|---|---|
| Data processed | IP address, device and browser data, data about your interaction with the embedded video. |
| Purpose | Video playback; Google may also use data for analytics and advertising – find out more about our use of cookies in our Cookie policy. |
| Legal basis | Your consent via our cookie banner |
| Controller status | Google LLC acts as an independent controller for its own processing purposes. |
| International transfer | Data are transferred to the United States; Google LLC is certified under the EU–U.S. Data Privacy Framework. |
| Retention | Stored until manually deleted by the user via the browser settings |
Important: We only allow YouTube to set non-essential cookies after you have given consent via our cookie banner.
When you submit a message via our contact form, we use the information you provide solely to respond to your enquiry.
| Element | Details |
|---|---|
| Data processed | Name, email address, message content |
| Purpose | Responding to your enquiry |
| Legal basis | Legitimate interest*: responding to an inbound communication request |
| Retention | Deleted when no longer necessary for responding to your enquiry, unless a longer statutory retention obligation applies |
| Processor | Squarespace (email/contact form hosting). See 5. Processors. |
| Element | Details |
|---|---|
| Data processed | Name, email address, shipping address, billing address, order history, payment data (processed via the webshop's payment provider). |
| Purpose | Processing and fulfilling orders placed through the embedded webshop, including payment handling, shipping, and order administration. |
| Legal basis | Performance of a contract: processing is necessary to fulfil the order placed by the visitor. |
| Controller & processor | MyClusters acts as controller for the data collected through the webshop. Printful acts as an (independent) controller with regard to the merchant data (payment data, contact details, account information). |
| International transfer | Data might be transferred outside the EU (UK, United States), SCCs apply. |
| Retention | For the duration of your account, subject to statutory obligations |
When you create an account and use the MyClusters app, we process additional personal data, including special categories of data (health information). This section provides transparent information regarding our processing activities.
What we process and why
| Element | Details |
|---|---|
| Data processed | Email address, password (hashed), app usage data, device/session identifiers, DOB, Gender Health information such as date and time of the cluster headache, triggers, symptoms and medication used. |
| Purpose | Creating and managing your account; providing the MyClusters service |
| Legal basis | Account information: performance of a contract. Processing is necessary to be able to use the app. Health information: consent of the user of the app |
| Retention | For the duration of your account, subject to statutory obligations |
| Processors | AWS (cloud storage), Fly.io (hosting). See 5. Processors. |
To improve the MyClusters app and optimise the onboarding experience, we collect pseudonymised usage data through an analytics platform. This data helps us understand how the app is used, identify areas for improvement, and evaluate the effectiveness of new features through controlled experiments (A/B testing).
| Element | Details |
|---|---|
| Data processed | Pseudonymous user ID, install UUID, device ID, session ID. User properties: app variant, platform, language. Event data: signup method (password / Google / Apple), email verification status, onboarding navigation (steps and screens viewed, skipped or completed, duration), research consent choice (given or skipped), goals configuration (count and goal keys, no health data), and experiment exposure data (flag key and variant). |
| Purpose | App analytics and performance improvement; onboarding optimisation; A/B testing of app features. |
| Legal basis | Consent. The Amplitude SDK is not initialised until you have given your consent. |
| Retention | Event data is retained in Amplitude for 12 months after which it is automatically deleted. Pseudonymous identifiers are retained for the duration of your account and are deleted within 30 days of account deletion. |
| Processors | Amplitude. See 5. Processors. |
Under the GDPR, you have the following rights regarding the processing of your personal data. You can exercise any of these rights by contacting us using the details at the bottom of this section.
Do you have questions, comments, requests or complaints about the processing of your personal data or this privacy statement? Please contact us at privacy@myclusters.nl.
We take the protection of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against loss, misuse, unauthorised access, alteration, disclosure or destruction. These measures are continuously reviewed and improved in line with technological developments. Access to personal data is strictly limited to employees and third parties, such as research partners and pharmaceutical companies, who are bound by contractual confidentiality obligations. Your personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required for tax or legal reasons.
In the context of patient stratification research, we apply additional safeguards to mitigate the risk of unauthorised identification. Where data is shared with research or pharmaceutical partners, we apply data masking techniques (replacing direct identifiers such as your name with a pseudonymous reference code) so that your identity is not directly apparent to the recipient. This data remains personal data under the GDPR, and all recipients are required to treat it as such. Additional safeguards include an internal policy governing the sharing of and access to research data; mandatory declarations by all researchers prohibiting any attempt to re-identify individuals and confirming compliance with applicable privacy legislation; a review of all questionnaires prior to distribution to assess re-identification risk; and contractual clauses with all research and pharmaceutical partners explicitly prohibiting re-identification and requiring appropriate data protection measures.
In order to provide and improve our website and services, we may share your personal data with carefully selected sub-processors who process data on our behalf. We only share personal data to the extent necessary for the relevant purpose. All (sub-)processors are contractually bound to comply with the General Data Protection Regulation (GDPR) and to implement appropriate technical and organisational measures to protect your personal data.
We engage the following categories of (sub)processors:
Some of our (sub)processors are located outside the European Economic Area (EEA), in particular in the United States, or are part of organisations incorporated in the United States. Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR. This includes the use of Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, reliance on certification under the EU–U.S. Data Privacy Framework.
If you have any questions or comments about our Statement, please send us an e-mail at privacy@myclusters.nl.
You may also contact us by postal mail at:
MyClusters BV
Langegracht 70
2312 NV, Leiden
The Netherlands
Chamber of Commerce: 94966958
MyClusters has appointed a Data Protection Officer (DPO) to oversee our data protection practices and ensure compliance with the GDPR. Our DPO acts independently and is not subject to instructions from MyClusters' management regarding the exercise of their tasks.
If you have questions about how we process your personal data, wish to exercise your rights under the GDPR, or have concerns about data protection, you can contact our DPO directly:
Data Protection Officer
MyClusters B.V.
E-mail: dpo@myclusters.nl
Postal address: Langegracht 70, 2312 NV Leiden, The Netherlands
We may update this privacy statement from time to time to reflect changes in our data processing practices, legal requirements or the services we offer. If we make material changes to this statement or the way in which we process your personal data, we will notify you in advance through a prominent notice, for example via email or a notification within our platform, before the changes take effect. The date of the most recent version of this statement is indicated at the top of this page. We encourage you to review this statement periodically to stay informed about how we protect your personal data.