Skip to content

Privacy Policy

Version 1.0
Last updated: 3 September 2026

1. Introduction

This Privacy Policy explains how personal information is collected, used, stored and protected when you use this website, the Tinnitus Assessment & Monitoring Portal, the Tinnitus Research & Outcomes system, and related tinnitus assessment services.

We recognise that tinnitus, hearing and other health-related information can be sensitive. We therefore aim to collect only information reasonably necessary for the services being provided and to handle it with appropriate confidentiality and security.

This Privacy Policy should be read together with our Terms of Use, Medical Disclaimer, Patient Consent & Data Processing information, Cookie Policy and, where applicable, Research Participant information.

2. Who is responsible for your information?

The data controller responsible for the operation of this website is:

Website: tinnitusscore.net
Email: info@tinnitusscore.net

The data controller determines why and how personal information is processed through this website.

Where a Doctor, audiologist, clinic, researcher, university or other organisation independently uses the Portal in connection with its own Patients or research participants, that organisation may also have its own responsibilities as a data controller.

In such circumstances, the organisation should provide its own privacy information where required.

3. Information we may collect

The information collected depends on how you use the website.

Website visitors

Information may include:

  • IP address;
  • browser and device information;
  • operating system;
  • approximate location derived from technical information;
  • pages visited;
  • website security and diagnostic information;
  • cookie preferences and consent choices.

Registered Patient accounts

Information may include:

  • first name;
  • last name;
  • email address;
  • telephone number;
  • country;
  • date of birth;
  • sex;
  • account information;
  • occupation;
  • occupational noise exposure;
  • recreational noise exposure.

Tinnitus and hearing information

Depending on the information provided by the Patient or Professional, the Portal may process:

  • presence and duration of tinnitus;
  • tinnitus laterality;
  • tinnitus pattern;
  • tinnitus character;
  • hearing-loss information;
  • hearing-aid use;
  • known tinnitus onset or associated event;
  • relevant otological history;
  • possible medication association;
  • clinical or monitoring notes;
  • questionnaire responses;
  • questionnaire scores;
  • questionnaire severity classifications;
  • assessment dates;
  • longitudinal assessment history.

This information may constitute health-related personal data.

THI and TFI assessments

The Portal may process responses and calculated results from tinnitus questionnaires including:

  • Tinnitus Handicap Inventory (THI);
  • Tinnitus Functional Index (TFI);
  • individual questionnaire responses;
  • calculated scores;
  • severity classifications;
  • TFI subscale scores where applicable;
  • assessment dates;
  • progress over time.

Questionnaire scoring may be performed automatically by the website.

These calculations assist assessment and monitoring. They do not constitute an automated medical diagnosis or a decision producing legal or similarly significant effects.

Doctor and Professional accounts

Professional account information may include:

  • first and last name;
  • email address;
  • professional title;
  • clinic or organisation;
  • professional registration or licence information where provided;
  • account status;
  • Patient relationships created through the Portal;
  • activity and audit information.

Doctors may also choose to complete private tinnitus self-assessments using their existing Professional account.

Consent information

Where consent or another authorisation is required, we may record information such as:

  • the person or account concerned;
  • consent status;
  • consent version;
  • date and time of confirmation;
  • method of confirmation;
  • person recording or verifying the consent;
  • withdrawal status and date where applicable;
  • relevant audit information.

4. Research information

The Tinnitus Research & Outcomes system is designed to support research datasets while reducing the use of directly identifiable Patient information.

Research records may include:

  • anonymous participant code;
  • age at baseline;
  • sex;
  • country or study country;
  • treatment group;
  • degree of hearing loss;
  • THI score;
  • baseline TFI score;
  • four-week TFI score;
  • three-month TFI score;
  • assessment dates;
  • hearing-aid datalogging information;
  • perceived tinnitus improvement or relief;
  • research-consent status;
  • study information;
  • research notes that should not contain direct identifiers.

Direct identifying information such as Patient name, email address, telephone number, postal address or date of birth should not be stored in the research participant dataset.

Spreadsheet imports containing obvious identifying columns may be rejected automatically.

Data imported from the Tinnitus Assessment & Monitoring Portal into a Research study is intentionally separated from the normal Patient account.

Patient names and other identifying information may be shown temporarily to an authorised administrator to identify the correct source record during an import, but those identifiers are not intended to form part of the resulting research participant record.

5. Research consent

Ordinary use of the Tinnitus Assessment & Monitoring Portal does not automatically mean that a Patient has agreed to participate in research.

Where information is used as part of a research study, appropriate study-specific research consent or another lawful research authorisation must be obtained where required.

The Research & Outcomes system records whether research consent has been verified.

Records without verified study-specific consent are excluded from public research calculations.

If verified research consent is subsequently withdrawn, the record may be excluded from subsequent research publication or processing where withdrawal applies, subject to applicable legal and research requirements.

6. Public research results

Research results made available publicly through this website are designed to be presented in aggregated form.

The public Research Results pages do not intentionally display:

  • Patient names;
  • email addresses;
  • telephone numbers;
  • postal addresses;
  • dates of birth;
  • Portal Patient IDs;
  • WordPress user IDs;
  • individual questionnaire answer records;
  • free-text clinical notes.

Results may instead be displayed as aggregated statistics, charts, means, participant counts, treatment-group comparisons and longitudinal outcome information.

Small subgroups may be suppressed to reduce the risk that an individual could be identified from the published information.

Studies may be displayed individually or, where methodology and outcome measures are sufficiently compatible, aggregated by country, year or across participating studies.

7. Why we process personal information

Personal information may be processed for purposes including:

  • creating and managing user accounts;
  • providing secure authentication;
  • providing tinnitus self-assessment tools;
  • saving THI and TFI assessments;
  • calculating questionnaire scores;
  • displaying progress over time;
  • allowing Patients to review their own information;
  • allowing authorised Professionals to manage relevant Patients;
  • allowing Patients to be found and connected with Professionals where this function has been authorised;
  • providing Doctor self-assessment functionality;
  • maintaining consent records;
  • providing research functionality where separately authorised;
  • generating anonymised or aggregated research results;
  • maintaining security;
  • detecting misuse or unauthorised access;
  • maintaining audit records;
  • providing password-reset and account emails;
  • responding to support requests;
  • complying with legal and regulatory obligations;
  • establishing, exercising or defending legal claims where necessary.

We do not use health information for unrelated advertising purposes.

8. Legal bases for processing

Different legal bases may apply depending on the type of information and the context in which it is processed.

These may include:

Consent

Consent may be relied upon where you voluntarily agree to specific processing.

For health-related information processed through Patient self-assessment functionality, explicit consent may be used where required.

Consent may be withdrawn, although withdrawal does not affect processing that was lawful before withdrawal.

Provision of a requested service

Certain account and contact information may be necessary to provide the website account or service requested by you.

Legitimate interests

We may process limited information where reasonably necessary for legitimate interests such as:

  • website and account security;
  • prevention of misuse;
  • technical operation;
  • maintaining audit information;
  • protecting the rights and security of users;
  • establishing or defending legal claims.

These interests are considered against the rights and freedoms of affected individuals.

Legal obligations

Information may be processed where necessary to comply with applicable legal, regulatory, accounting or professional obligations.

Healthcare or Professional processing

A healthcare Professional or clinic using the Portal may have additional lawful grounds for processing health information under applicable healthcare and professional laws.

Their own privacy notice and legal responsibilities may apply separately.

Scientific research

Research information will be processed according to the applicable research protocol, consent arrangements and legal basis for the particular study.

9. Patient directory and Professional access

Where a Patient has enabled the relevant Portal functions and provided the required consent, registered Professionals may be able to search for the Patient using information such as:

  • name;
  • telephone number;
  • email address.

A Professional may then add that Patient to their professional Patient list.

Authorised Professionals may be able to view relevant profile and tinnitus-assessment information made available through the Portal.

Removing a Patient from a Doctor’s list is not the same as deleting the Patient’s independent account.

A Doctor cannot obtain ownership of a Patient’s independent Portal account merely by adding the Patient to a Patient list.

10. Who may have access to information?

Access may be provided where necessary to:

  • the individual user;
  • authorised Doctors or Professionals;
  • authorised website administrators;
  • authorised researchers for an approved study;
  • technical service providers necessary to operate the website;
  • hosting providers;
  • email-delivery infrastructure;
  • security and backup providers where used;
  • cookie/consent-management providers;
  • analytics providers where enabled and consented to;
  • regulatory or legal authorities where disclosure is required by law.

Access should be limited to what is reasonably necessary for the relevant purpose.

11. Hosting and email

The website is currently hosted using server infrastructure located in Lithuania, European Union.

Portal email is currently sent through the website’s own server infrastructure using WordPress email functionality and FluentSMTP as the mail-delivery interface.

FluentSMTP does not determine the purpose for which Patient or assessment information is processed. Its role is to facilitate website email delivery according to the configured server settings.

Email may be used for purposes such as:

  • account registration;
  • account setup;
  • password resets;
  • Professional approval;
  • security notices;
  • important service communications.

Sensitive clinical information should not normally be included unnecessarily in ordinary email messages.

12. Cookies and similar technologies

The website may use cookies or similar technologies.

Some cookies are technically necessary for the operation and security of WordPress and user accounts. These may support functions such as:

  • authentication;
  • login sessions;
  • security;
  • user preferences;
  • cookie-consent preferences.

Where non-essential cookies are used, they should be controlled through the website’s cookie-consent system.

We currently use Cookie Compliance for WordPress as our cookie-consent management solution.

Cookie Compliance allows visitors to manage their cookie preferences.

Depending on the Cookie Compliance configuration used by the website, consent-management information may be stored locally on the website or processed through services provided by the Cookie Compliance provider.

You can review or change available cookie choices through the cookie controls provided on the website.

For detailed information about individual cookies, their purposes and their duration, please see our Cookie Policy and the cookie-preference interface.

13. Google services

The Tinnitus Assessment & Monitoring Portal, Tinnitus Research & Outcomes plugin and standalone THI/TFI questionnaire do not themselves require Google Analytics in order to function.

However, the wider website may use Google services where separately enabled by the website administrator.

These may include services such as:

  • Google Analytics;
  • Google Tag Manager;
  • Google reCAPTCHA;
  • YouTube or other embedded Google content.

The exact services used may change according to website configuration.

Where Google Analytics or other non-essential Google technologies require consent, they should not be activated for a visitor until the appropriate cookie or privacy choice has been made through the site’s consent-management system.

Google services may process information such as:

  • cookie or device identifiers;
  • browser and device information;
  • approximate location;
  • website interaction information;
  • IP-related technical information.

Please refer to the Cookie Policy and cookie-preference system for the Google services currently active on this website.

14. International transfers

Our primary website hosting is currently located within the European Union.

However, some optional external services, including certain analytics, embedded-content, security, payment or technology providers, may process information outside the European Economic Area.

Where such transfers occur, appropriate safeguards or another valid transfer mechanism should be used where required by applicable data-protection law.

The service providers and technologies used by the website may change over time, and this Privacy Policy and Cookie Policy should be updated where those changes materially affect the processing of personal information.

15. How long information is retained

Personal information is not intended to be retained indefinitely without a purpose.

Retention periods depend on the type of information and why it is required.

Account and Portal information may generally be retained:

  • while the account remains active;
  • while required to provide the requested service;
  • while relevant clinical or monitoring records legitimately need to be maintained;
  • until a valid deletion request is completed where the information can lawfully be erased;
  • for longer where a legal, professional, research, security or regulatory obligation requires retention.

Research information may be retained according to the relevant research protocol, ethical requirements, academic requirements and applicable law.

Consent and audit records may be retained where reasonably necessary to demonstrate that appropriate consent, authorisation or actions occurred.

Technical backups may retain information temporarily until the relevant backup cycle expires.

We periodically review whether retained information remains necessary.

16. Data accuracy

Users are encouraged to ensure that account information is accurate and to update incorrect or outdated information where the Portal permits.

Where information cannot be corrected directly, users may contact us.

Research data may be corrected by authorised research administrators.

Important changes to research records may be recorded in an audit history so that corrections do not silently remove evidence of previous research values.

17. Security

We use technical and organisational safeguards intended to protect information against:

  • unauthorised access;
  • accidental loss;
  • inappropriate alteration;
  • unlawful disclosure;
  • misuse.

Measures may include:

  • account authentication;
  • role-based access;
  • separation of Patient and Professional permissions;
  • server security;
  • software updates;
  • database access controls;
  • audit records;
  • secure password-reset mechanisms;
  • anonymisation or pseudonymisation for research use where appropriate.

No internet-based system can guarantee absolute security.

Users are responsible for keeping their own passwords confidential and should notify us if they believe their account has been compromised.

18. Automated questionnaire processing

THI and TFI questionnaire scores are calculated automatically according to the configured questionnaire scoring rules.

The system may also automatically:

  • calculate severity categories;
  • calculate TFI subscale scores;
  • generate progress graphs;
  • calculate aggregated research statistics;
  • suppress public research subgroups below defined privacy thresholds.

These automated calculations are intended for assessment, monitoring and research presentation.

They do not automatically diagnose a disease, prescribe treatment or make a legal or similarly significant decision about a person.

19. Your data-protection rights

Subject to applicable law and any relevant exceptions, you may have rights including:

  • the right to be informed about processing;
  • the right to access your personal information;
  • the right to correct inaccurate or incomplete information;
  • the right to request deletion of information;
  • the right to request restriction of processing;
  • the right to object to certain processing;
  • the right to receive certain information in a portable format;
  • the right to withdraw consent where processing relies on consent;
  • rights relating to certain automated decisions.

A request may require reasonable identity verification before information is released, changed or deleted.

Requests should be sent to:

info@tinnitusscore.net

We will respond in accordance with applicable data-protection law.

20. Account deletion and data export

Where available, registered users may use the Portal’s privacy functions to request an export of their information or request account deletion.

Deleting or removing one relationship does not necessarily delete another person’s independent information.

For example:

  • removing a Patient from a Doctor’s Patient list does not automatically delete the Patient account;
  • deleting a Doctor account does not automatically delete independent Patient accounts;
  • research information may be subject to separate consent, research and retention requirements.

Where information cannot lawfully be erased, we may retain only what is necessary for the applicable obligation.

21. Withdrawal of consent

Where processing relies on consent, you may withdraw that consent.

Withdrawal does not retrospectively invalidate processing that lawfully occurred before the withdrawal.

Withdrawal may affect the availability of functions that require the relevant information.

Research-consent withdrawal will be handled according to the relevant research protocol and applicable law.

22. Complaints

If you have concerns about how your personal information is processed, please contact us first so that we can investigate the matter.

You also have the right to lodge a complaint with the competent supervisory authority.

For Cyprus, the supervisory authority is:

Office of the Commissioner for Personal Data Protection
15 Kypranoros Street
1061 Nicosia
Cyprus

Postal address:
P.O. Box 23378
1682 Nicosia
Cyprus

Telephone: +357 22 818456

Official supervisory-authority contact information should be checked from the Commissioner’s website before submitting a complaint.

23. Standalone tinnitus questionnaires

The standalone THI/TFI questionnaire tool available on this website is designed so that questionnaire responses are processed within the visitor’s browser.

The standalone tool does not intentionally transmit or save individual questionnaire answers to the website database.

This is different from questionnaires completed while signed into the Tinnitus Assessment & Monitoring Portal, where assessments may be stored as part of the user’s Portal record.

24. Questionnaire ownership

The website may provide recognised tinnitus questionnaires, including the Tinnitus Handicap Inventory (THI) and Tinnitus Functional Index (TFI).

Questionnaire names, wording, scoring systems and associated intellectual property may remain the property of their respective authors, institutions or rights holders.

The processing of questionnaire responses through this website does not transfer ownership of those instruments to the website operator.

25. Changes to this Privacy Policy

We may update this Privacy Policy when:

  • website functionality changes;
  • new services are introduced;
  • new service providers are used;
  • research functionality changes;
  • legal or regulatory requirements change.

The current version and revision date will be displayed at the beginning of this page.

Where a change materially affects processing that depends on consent, users may be asked to review updated information or provide renewed consent where appropriate.

26. hCaptcha

We use the hCaptcha security service (hereinafter “hCaptcha”) on our website. This service is provided by Intuition Machines, Inc., a Delaware US Corporation (“IMI”). hCaptcha is used to check whether user actions on our online service (such as submitting a login or contact form) meet our security requirements. To do this, hCaptcha analyzes the behavior of the website or mobile app visitor based on various characteristics. This analysis starts automatically as soon as the website or mobile app visitor enters a part of the website or app with hCaptcha enabled. For the analysis, hCaptcha evaluates various information (e.g. IP address, how long the visitor has been on the website or app, or mouse movements made by the user). The data collected during the analysis will be forwarded to IMI. hCaptcha analysis in the “invisible mode” may take place completely in the background. Website or app visitors are not advised that such an analysis is taking place if the user is not shown a challenge. Data processing is based on Art. 6(1)(b) of the GDPR: the processing of personal data is necessary for the performance of a contract to which the website visitor is party (for example, the website terms) or in order to take steps at the request of the website visitor prior to entering into a contract. Our online service (including our website, mobile apps, and any other apps or other forms of access offered by us) needs to ensure that it is interacting with a human, not a bot, and that activities performed by the user are not related to fraud or abuse. In addition, processing may also be based on Art. 6(1)(f) of the GDPR: our online service has a legitimate interest in protecting the service from abusive automated crawling, spam, and other forms of abuse that can harm our service or other users of our service. IMI acts as a “data processor” acting on behalf of its customers as defined under the GDPR, and a “service provider” for the purposes of the California Consumer Privacy Act (CCPA). For more information about hCaptcha’s privacy policy and terms of use, please visit the following links: https://www.hcaptcha.com/privacy and https://www.hcaptcha.com/terms.

27. Contact

For privacy, data-access, correction, export, deletion or consent questions, contact:

Privacy contact: Site Admin
Email: info@tinnitusscore.net
Website: tinnitusscore.net