Privacy & Data Protection Policy
Quick Overview
This document explains how Elderwise collects, uses, and protects your personal data in accordance with applicable data protection laws, including GDPR and CCPA/CPRA.
1. Definitions
Under this Privacy Policy, the following terms have specific meanings:
Term | Definition |
---|---|
Personal Data | Any information relating to an identified or identifiable natural person. |
Controller | The entity that determines the purposes and means of processing personal data. |
Processor | The entity that processes data on behalf of the Controller. |
Processing | Any operation performed on personal data, such as collection, recording, organization, storage, etc. |
Data Subject | The identified or identifiable person to whom the personal data relates. |
2. Information We Collect
We collect personal information that you voluntarily provide to us when you express interest in obtaining information about our products and services, when you participate in activities on our website, or otherwise when you contact us.
The personal information we collect may include:
- Name and contact data (such as your email address, phone number, etc.)
- Credentials (such as passwords and similar security information used for authentication)
- Business information (such as company name, job title, etc.)
- Health and medical information (with appropriate consent) when using our caregiving services
- Device and connectivity information when using our platform
3. How We Process Your Information
As the Controller of your data, we process your personal information for these purposes:
- To provide and deliver our services, including to process transactions
- To respond to your inquiries and provide customer service
- To send administrative information, such as updates, security alerts, and support messages
- To personalize your experience and deliver content relevant to your interests
- To improve our website, products, services, marketing, and customer relationships
- To protect our rights, interests, safety, and property
- To comply with legal requirements and industry standards
Legal Basis for Processing
We process your personal data based on: your consent, the necessity to perform our contract with you, compliance with our legal obligations, or our legitimate interests (which we balance against your rights and freedoms).
We will only process Personal Data in accordance with this Privacy Policy and your instructions (unless legally required to do otherwise). We will notify you promptly if we believe any of your instructions may infringe Data Protection Laws.
6. Your Rights
Depending on your location and applicable law, you may have the following rights:
- Right to Access - You can request copies of your personal data.
- Right to Rectification - You can request that we correct inaccurate information about you.
- Right to Erasure - You can ask us to delete your personal information in certain circumstances.
- Right to Restrict Processing - You can ask us to limit how we use your personal information.
- Right to Data Portability - You can ask for a copy of the information you provided to us in a machine-readable format.
- Right to Object - You can object to our processing of your personal information.
We will respond to your request within the Breach Notification Period (30 days for GDPR, 45 days for CCPA/CPRA), which may be extended if necessary.
To exercise any of these rights, please contact us at privacy@elderwise.ai. We may need to verify your identity before responding to your request.
7. International Data Transfers
We may transfer Personal Data outside the UK, the EEA or other countries with adequate data protection laws. When we do, we implement appropriate safeguards:
- Standard Contractual Clauses approved by the European Commission
- Binding Corporate Rules
- Approved codes of conduct
- Additional supplementary measures as needed
If the Transfer Mechanism is insufficient to safeguard the transferred Personal Data, we will promptly implement supplementary measures to ensure Personal Data is protected to the standard required under applicable Data Protection Laws.
8. Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include encryption, access controls, security testing, and regular security assessments.
Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
Trust & Privacy Note
All data is HIPAA-compliant, encrypted at rest and in transit. You own it; we simply help you use it.
9. Updates to This Policy
We may update this privacy policy from time to time. The updated version will be indicated by an updated "Last Updated" date and the updated version will be effective as soon as it is accessible. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
If we make material changes to this policy, we will notify you either through the email address you have provided us, or by placing a prominent notice on our website.
Contact Us
If you have questions about this policy or our privacy practices, you can contact our Data Protection Officer at:
Elderwise, Inc.
Attn: Data Protection Officer
privacy@elderwise.ai