Privacy · Articles 13 and 14 GDPR

We do not collect your data.

No cookies, no analytics, no advertising, no tracker, no account and no form. Reading this site leaves nothing with us, and you meet no consent banner because there is nothing to consent to. This page says what little is processed anyway, what our registers name, and how to exercise your rights. Questions go to info@dysnet.org.

Version of 17 September 2026; earlier versions stay in the public history of this site. The controller is DysNet Ideell Förening, organisation number 802444-3015, Nybodagatan 1, 171 42 Solna, Sweden, with an office at Rue du Chantier 2, B-1000 Brussels. We have appointed no data protection officer, and we will name one before the registry begins processing health data.

01 · The site

What happens when you read a page.

  • Your request reaches our host, not us. GitHub Pages serves these files, so GitHub receives what every web request carries: your IP address, the time, the page and your browser. It uses that to deliver the page and to protect the service. We keep no visitor database and receive nothing visitor-level, so nobody here can look up who read what. Legal basis: our legitimate interest in a website that works, Article 6(1)(f). The site is static files with no database and no login, served over HTTPS.
  • One thing is remembered, and it stays on your device. On the pages with a map, your browser keeps the word open or closed so the information card stays as you left it. It carries no identifier, it never reaches us, and it disappears when you close the tab.
  • Videos wait for you. Nothing loads from Google until you press play. Then Google receives your IP address and device information under its own policy.

02 · Email

If you write to us.

Our mail runs on Zoho's European service, with Zoho Corporation B.V. in Utrecht as our processor. We read your message and answer it, and we keep the thread. We do not delete correspondence on a timer, because a question from a family or an association often resumes years later and that record is part of what the network is for. You can ask us to erase your correspondence at any time, and we will. Membership and donation records that count as accounting information stay for the seven years after the end of the calendar year in which the financial year closed, which Swedish law requires (Bokföringslag 1999:1078, chapter 7).

Legal bases: answering the people who write to us, Article 6(1)(f); membership, donations and agreements, Article 6(1)(b) and (c). If you describe your own or your child's condition, you are sending health data. We may hold it because we are a non-profit body with a health aim, acting for our members and the people in regular contact with us, and because we disclose it to nobody outside (Article 9(2)(d)). Write in general terms if you would rather. We ask for no medical detail we do not need.

03 · Registers

The registers name professionals, not patients.

Some of what we publish concerns named professionals we never asked, and Article 14 requires us to say so. The researcher register holds 109 research teams with their institution, country, the surnames and initials of first and last authors and their publications on our conditions, taken from the affiliations recorded in PubMed. The bibliography holds 1,844 references with their authors as published. The studies page carries the contact each study gives for itself, member associations the addresses they publish for themselves, and People our board and the volunteers who maintain the registers. Care centres and registries name institutions only.

Legal basis: our legitimate interest, Article 6(1)(f), in publishing a free resource on conditions too few people study. We keep to professional information its holders have already published in a professional capacity, and we publish nothing about anyone's health. To be corrected or removed, write and name the entry: we act within 30 days and ask you for no reason. One limit we state openly, because the registers are open data under CC BY 4.0: a copy downloaded before a removal stays with whoever took it.

04 · No wall

The registers stay open.

We considered putting the registers behind an analytics tracker you would have to accept. We had the question tested first, and it cannot be done lawfully. It would also be wrong: these pages describe a health condition, so a record that you read them would say something about your own or your child's health. A family looking up a diagnosis at two in the morning owes us nothing in exchange.

Should we ever measure our traffic, we will count pages rather than people, and say so here before we start.

Why it is unlawful, for the reader who wants it: Swedish law allows an identifier to be stored on your device only with your consent, or where that is strictly necessary for the service you asked for (9 kap. 28 § lagen (2022:482) om elektronisk kommunikation). Consent extracted by withholding the content is not freely given (European Data Protection Board guidelines on consent of 4 May 2020, paragraphs 39 to 41).

05 · The registry

Nothing is collected yet.

The limb-malformation registry does not exist, and no health data reaches us through this site. When it opens it will carry its own notice, published before the first family enters anything. Four things will hold.

  • Each person holds their own account and decides what goes into it.
  • Consent is explicit, given study by study, and withdrawable at any time (Article 9(2)(a)).
  • No association enrols anybody. Families are invited, and they enter their own information.
  • We do not sell the data, and we will not pass it to insurers or employers. Bulk access without the consent of the people described will not be possible.

The technical partner is Health Data Safe. Its statutes rule out any sale of health data and limit its use to care and research, and they provide that personal data is never treated as an asset of the foundation.

06 · Your rights

What you can ask, and whom to tell.

You may ask us to do any of this, and Article 15 to Article 21 GDPR give you the right:

  • give you a copy of what we hold about you, or correct it;
  • erase it, or stop using it while a question about it is open;
  • hand it over in a form you can take elsewhere;
  • stop processing that rests on our legitimate interest.

In the registry, you will not have to ask us. These rights are part of how the registry is built rather than a procedure wrapped around it. Each person holds their own account at Health Data Safe, and from it they review, correct, export and delete their own data, and withdraw a consent to share, without writing to anybody. Health Data Safe already publishes a self-service download of everything in an account and a route to delete it. Until the registry opens, the rights above are exercised by writing to us, and we carry them out by hand.

Consent, where we rely on it, can be withdrawn at any time. Write to info@dysnet.org. We answer within one month, free of charge, and if a request is genuinely complex we say so inside that month (Article 12(3)). We take no automated decisions about anybody and we build no profiles.

Only two others ever touch anything: GitHub hosts the site from the United States, and states that it complies with the EU-US Data Privacy Framework, and Zoho carries our mail on its European service. Nobody else. We use no advertising network, no analytics provider, no data broker and no mailing-list service, and we have never sold or rented personal data.

If we get something wrong, tell us, because most of it we can simply fix. You may also complain to a supervisory authority, choosing the one where you live, where you work or where you think the problem happened (Article 77), and you may go to court (Article 79). Ours is Integritetsskyddsmyndigheten, the Swedish Authority for Privacy Protection: Box 8114, 104 20 Stockholm, imy@imy.se, +46 8 657 61 00, which takes complaints through its own form.