Date of last revision: September 19, 2014
This Privacy Notice describes how AliveCor, Inc. and its subsidiaries and affiliates (collectively “AliveCor,” “AliveCor,” “us”) collects, processes, uses, discloses, and secures information through its mobile app (the “App”) and its websites, including http://www.alivecor.com and http://www.alivecorvet.com (the “Sites”) (collectively the “Services”).
There are many different ways you can use AliveCor’s Services – to record ECGs, request an ECG analysis report, email ECGs, and grant access to your providers. In order to deliver the Services to you, AliveCor require you to consent to the collection and processing of your personal information when you initially begin using them. Your information is stored in two locations in order to provide you with the Services: your mobile device and AliveCor’s secure, encrypted cloud server. As you use AliveCor’s Services, AliveCor want you to be clear about how AliveCor are using information and the ways in which you can protect your privacy.
AliveCor’s Privacy Notice explains:
- What information AliveCor collect and why AliveCor collect it.
- How AliveCor use that information.
- The choices AliveCor offer regarding AliveCor’s use of the information.
- The measures AliveCor take to protect the security of the information.
AliveCor’ve tried to keep it as simple as possible, but if you’re not familiar with terms like cookies, IP addresses, pixel tags and browsers, then read about these keyterms first.
Your privacy matters to AliveCor, so whether you are new to AliveCor or a long-time user, you can get to know AliveCor’s practices below, and contact us at firstname.lastname@example.org if you have any questions.
Information AliveCor Collect
AliveCor may collect the following types of personal information from users of AliveCor’s Services, and store it on your mobile device and in the secure and encrypted AliveCor database:
- Contact information (such as name, postal address, email address, and mobile or other telephone number) of individuals such as medical professionals, human patients and/or their parents or guardians, caretakers of veterinary patients and other visitors;
- Username and password;
- Information in customer support inquiries;
- Human patient demographics such as date of birth and gender;
- Human patient medical data such as medications and ailments;
- Payment information (such as payment card number, expiration date, delivery address, and billing address);
- Information about your device, such as its model and operating system version; and
- Information collected by the Services, including personal information (such as human electrocardiography (‘ECG’) data, including the ECG measurement itself, mobile device accelerometer data, average heart rate, the location on the body where the ECG recording was taken (e.g. hand or chest), local time, time zone and geographic location of ECG acquisition).
When you visit AliveCor’s Services or open AliveCor’s emails, AliveCor may collect certain information by automated means, such as cookies, web beacons and web server logs. The information AliveCor collect in this manner includes IP address, browser characteristics, device characteristics, operating system version, language preferences, referring URLs, information on actions taken on AliveCor’s Services, and dates and times of website visits. The information does not identify you. If you continue to use AliveCor’s Services, AliveCor will assume that you permit this collection. If you want to use the Services without cookies you may opt out at http://alivecor.com/privacy. Please note, however, that without cookies you may not be able to use all of the features of AliveCor’s Services.
A ‘cookie’ is a file that websites send to a visitor’s computer or other Internet-connected device to uniquely identify the visitor’s browser or to store information or settings in the browser. A ‘web beacon’ also known as an Internet tag, pixel tag or clear GIF, links web pages to web servers and their cookies and may be used to transmit information collected through cookies back to a web server. Through these automated collection methods, AliveCor obtain ‘clickstream data,’ which is a log of the links and other content on which a visitor clicks while browsing a website and identifies the prior website used to access the Services. As the visitor clicks through the Services, a record of the action may be collected and stored. AliveCor may link certain data elements AliveCor have collected through automated means with other information AliveCor have obtained about you to let us know, for example, whether you have opened an email AliveCor sent to you.
AliveCor may use third-party web analytics services on AliveCor’s Services, such as those of Google Analytics. The analytics providers that administer these services use technologies such as cookies, web server logs and web beacons collect usage information matched to an IP address, but not your personal information, to help us analyze how visitors use the Sites and improve the overall experience of the Sites. The analytics providers may also collect information about your use of other websites over time, if those websites also use the same analytics providers. To learn more about Google Analytics and how to opt out, please visit http://www.google.com/analytics/learn/privacy.html.
AliveCor may use third-party services on AliveCor’s Services, such as MixPanel, to collect usage data in order to understand and continue improving AliveCor’s products and services. To learn more about MixPanel, please visit https://mixpanel.com/privacy/.
How AliveCor Use the Information AliveCor Collect
AliveCor may use the information AliveCor collect to:
- Create and manage accounts;
- Provide products and services, and give access to the ECG analysis service;
- Deliver and manage customer support and respond to inquiries;
- Process payments;
- Send promotional materials or other communications, communicate about, and administer participation in, special events, programs, offers, surveys and market research;
- Perform data analyses (including de-identification and aggregation of personal information);
- Operate, evaluate and improve AliveCor’s business (including developing new products and services; enhancing and improving AliveCor’s services; managing AliveCor’s communications; analyzing AliveCor’s products; and performing accounting, auditing and other internal functions);
- Aggregate and anonymise information and images and use and share the resulting data for business purposes (for example, to provide beneficial health-related data not limited to statistics, trending and services to AliveCor affiliates);
- Protect against, identify and prevent fraud and other unlawful activity, claims and other liabilities; and
- Comply with and enforce applicable legal requirements, relevant industry standards and AliveCor’s policies.
AliveCor will retain your personal information even if you cease using the Services until such time as you notify us, as indicated in the ‘How to Contact Us’ section of this Privacy Notice, of your intention to cease using the Services indefinitely. Even after you notify us of your intention to cease using the Services, AliveCor will retain and continue to use aggregated and anonymised information and images.
Information AliveCor Share
AliveCor do not sell or otherwise disclose personal information AliveCor collect about you, except as described in this Privacy Notice. AliveCor do not rent, sell, or share personal information about you with other people or nonaffiliated companies for their direct marketing purposes, unless AliveCor have your permission.
AliveCor share your information with other users, such as healthcare providers, if you explicitly give permission for them to access your ECGs through the Services or you choose to email them your ECGs.
AliveCor also may share personal information with vendors and service providers who perform services for us in connection with the provision of the Services based on AliveCor’s instructions. Examples of these vendors and service providers include entities that analyze ECG data to detect cardiac rhythms, process credit card payments, fulfill orders and provide web hosting services. AliveCor do not authorize these vendors or service providers to use or disclose the personal information except as necessary to perform services on AliveCor’s behalf or comply with legal requirements.
In addition, AliveCor may access, preserve, and disclose information about you (i) if AliveCor are required to do so by law or legal process, (ii) to law enforcement authorities or other government officials, (iii) when AliveCor believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity, and (iv) to protect your, AliveCor’s, or others’ rights, property or safety.
In the event AliveCor sell or transfer all or a portion of AliveCor’s business or assets (including in the event of a reorganization, dissolution or liquidation), such assets likely will include the data AliveCor retain. AliveCor will use reasonable efforts to direct the transferee to use personal information you have provided to us in a manner that is consistent with this Privacy Notice. Following such a sale or transfer, you may contact the entity to which AliveCor transferred your personal information with any inquiries concerning the processing of that personal information.
Your Rights and Choices
AliveCor offer you certain choices in connection with the personal information AliveCor collect from you, such as how AliveCor use the personal information and how AliveCor communicate with you. To update your email preferences, ask us to remove your personal information from AliveCor’s mailing lists or submit a request, please contact us as indicated in the ‘How to Contact Us’ section of this Privacy Notice.
Users with online accounts may be able to update or delete certain personal information using the Services. You may request access to the personal information AliveCor maintain about you or request that AliveCor correct, amend, delete or block the information by contacting us as indicated below by submitting a request via the ‘How to Contact Us’ section of this Privacy Notice. Any access request may be subject to a fee of £10 ($15 USD) to meet AliveCor’s costs in providing you with details of the personal information AliveCor hold about you. You may withdraw any consent you previously provided to us or object at any time on legitimate grounds to the processing of your personal information, and AliveCor will apply your preferences going forward. To exercise any of these rights, please submit a request via the ‘How to Contact Us’ section of this Privacy Notice.
Data Sharing Confirmation
To facilitate secure sharing of data to a health professional, AliveCor may contact you by email to confirm a request to do so. You have the ability to accept or reject those requests. If you wish to retract sharing of your data, please submit a request via the ‘How to Contact Us’ section of this Privacy Notice.
It is your health professional’s responsibility to ensure a sharing request is accepted by contacting you independently of any AliveCor service. Your ECG history will not be shared automatically, your health professional will only see new recordings from the time you accepted the request to share such information.
AliveCor may transfer personal information AliveCor collect about you to countries other than the country in which the personal information originally was collected. Those countries may not have the same data protection laws as the country in which you initially provided the personal information. If you are located in the United States, your data will be maintained and processed in the United States. If you are located in the EU, your data will be maintained and processed in Ireland. When AliveCor transfer your personal information to other countries, AliveCor will put in place measures to adequately protect that personal information as described in this Privacy Notice so that same level of protection is applied to that personal information as would be required were it processed in the country in which the personal information was originally collected.
How AliveCor Protect Personal Information
AliveCor maintain administrative, technical and physical safeguards designed to protect the personal information you provide against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use.
Links to Other Websites and Applications
The Services may provide links to other websites and applications for you convenience and information. These websites and applications may operate independently from us. Linked sites and applications may have their own privacy notices or policies, which AliveCor strongly suggest you review. To the extent any linked websites or applications are not owned or controlled by us, AliveCor are not responsible for the sites’ or applications’ content, any use of the sites or applications, or the privacy practices of the sites or applications.
Updates to AliveCor’s Privacy Notice
This Privacy Notice may be updated periodically and without prior notice to you to reflect changes to AliveCor’s information practices. AliveCor will post a prominent notice on AliveCor’s Services to notify you of any significant changes to AliveCor’s Privacy Notice and indicate at the top of the notice when it was most recently updated. Where required by law, AliveCor will seek your explicit consent to specific changes. You agree that AliveCor will reserve the right to occasionally notify you via email of any important changes to this Privacy Notice and/or Service agreements.
How to Contact Us
If you have any questions or comments about this Privacy Notice, or if you would like us to update information AliveCor have about you or your preferences, please contact us by email at email@example.com. You also may write to:
30 Maiden Lane, 6th Floor
San Francisco, CA 94108