AliveCor Privacy Policy

EFFECTIVE DATE: April 30, 2020

Welcome to AliveCor! This Privacy Policy (“Policy”) describes how AliveCor, Inc. (“we,” “us,” or “our”) collects, uses, and discloses information that we obtain about your use of the alivecor.com website (the “Site”), Kardia™ (“the App”), KardiaPro™ software (“KardiaPro”), collectively “the Service,” including information that we collect from the AliveCor devices (e.g., KardiaMobile®) that you connect to a mobile device running the App.

Does this Policy apply to you?


The Information We Collect About You. We collect information directly from you, from devices and third party services you connect, as well as automatically through your use of our Service.

When You Create, Update, or add information to Your Profile. When you register to use the Service, we collect the personal information you provide us, including your name, email address, password, gender, height, and birthdate. We also collect any additional information you choose to add to your profile, including: weight, body mass index (BMI), whether you are a smoker or non-smoker, medical conditions, information related to medications you are taking, patient ID, and activity levels.

We collect additional information from Devices you connect to your App:


How We Use Your Information

We process your information, including your personal information, for the following purposes:


How We Share Your Information. We may share your information, including personal information, as follows:


Privacy Shield Information For EU and Swiss Individuals

AliveCor complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States pursuant to the Privacy Shield. AliveCor has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit http://www.privacyshield.gov.

In compliance with the Privacy Shield Principles, AliveCor commits to resolve complaints about your privacy and our collection or use of your personal information pursuant to the Privacy Shield. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact AliveCor at the contact address below.

privacy@alivecor.com
AliveCor, Inc.
Attn. Privacy
444 Castro St #600
Mountain View, CA 94041

AliveCor has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit https://www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint.

Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.

The Federal Trade Commission has jurisdiction with enforcement authority over AliveCor’s compliance with the Privacy Shield.

The Privacy Shield Principles describe AliveCor’s accountability for personal data that it subsequently transfers to a third-party agent. Pursuant to the Privacy Shield Principles, AliveCor remains liable for the transfer of personal data to third parties acting as our agents unless we can prove we were not a party to the events giving rise to the damages.

Note that AliveCor may be required to release the personal data of EU and Swiss individuals pursuant to the Privacy Shield in response to legal requests from public authorities including to meet national security and law enforcement requirements.


Cookies

Cookies are small text files stored on your device and used by web browsers to deliver personalized content and remember logins and account settings. In addition to improving user experience, we use cookies and similar technologies for analytic and advertising purposes. You can manage your cookies locally by adjusting your browser settings, or you can opt-out of targeted advertising through cookies by visiting networkadvertising.org/choices or aboutads.info/choices. Because there is not yet a common understanding of how to interpret Do Not Track signals, we are unable to respond to Do Not Track requests from browsers, however we are monitoring for updates and will revisit this policy once a common standard is established.


Third-Party Links

Our Service may contain links to third-party websites. Any access to and use of such linked websites is not governed by this Privacy Policy, but instead is governed by the privacy policies of those third party websites. We are not responsible for the information practices of such third party websites.


Security of My Personal Information

We have implemented reasonable precautions to protect the information we collect from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Please be aware that despite our best efforts, no data security measures can guarantee security.

You should take steps to protect against unauthorized access to your password, phone, and computer by, among other things, signing off after using a shared computer, choosing a robust password that nobody else knows or can easily guess, and keeping your log-in and password private. We are not responsible for any lost, stolen, or compromised passwords or for any activity on your account via unauthorized password activity.


Access to, Storage of and Deleting My Personal Information

You may access and modify personal information that you have submitted by logging into your account and updating your profile information. Please note that copies of information that you have updated, modified or deleted may remain viewable in cached and archived pages of the Service for a period of time. Your personal data including EKG data are stored and accessible on your device as well as in the cloud.

We store information associated with your account until your account is deleted. You can delete your account at any time by contacting Customer Support at privacy@alivecor.com. Please note that it may take a bit of time to delete your account information, and we may preserve it for legal reasons or to prevent harm, including as described in the How Information Is Shared section.


What Choices Do I Have Regarding Promotional and Informational Emails?

We may send periodic promotional or informational emails to you. You may opt-out of such communications by following the opt-out instructions contained in the email. Please note that it may take up to 10 business days for us to process opt-out requests. We may still send you emails about your account or any services you have requested or received from us.


Users Under 18

Our services are not designed for users under 18. If we discover that a user under 18 has provided us with personal information, we will delete such information from our systems.


Your California Privacy Rights.

This Privacy Policy complies with the California Consumer Privacy Act (CCPA), which requires that we provide California residents with notice that you have the right to:

More information regarding the: sources from which we collect personal information can be found above in the section titled “The Information We Collect About You”; business and commercial purposes for which we collect your personal information can be found above in the section titled “How We Use Your Information”; categories of recipients with whom personal information is shared or sold can be found in the section above titles “How We Share Your Information.”

We do not sell any personal information collected from your use of the AliveCor Service.

We do use cookies on our website that collect and share information collected from your browser for behavioral targeting which is a “sale” under the CCPA. We will not do this if you click the “Do Not Sell My Personal Information” link on the website. In addition you can opt out of all collection of your data for behavioral advertising by visiting networkadvertising.org/choices or aboutads.info/choices.

To make a request under the California Consumer Privacy Act, or for any questions or concerns about our Privacy Policy or practices, please contact us at privacy@alivecor.com.


GDPR – Rights For EEA Users and AliveCor’s Capabilities for Worldwide Users

What Rights Do I Have? Individuals located in the European Economic Area (EEA) have certain rights in respect of your personal information. AliveCor will provide the capabilities to exercise these certain rights to all our worldwide users, including:

We rely on your consent as a lawful basis processing personal data for the following purposes:

We process personal data in order to perform our contract with you.

Additionally, we process personal data based on our contractual obligations to provide you the Service as described in the section “How We Use Your Information”, including:

In some cases, AliveCor may process personal information pursuant to a legal obligation or to protect your vital interests or those of another person.

For EEA users only per GDPR requirements, you can turn off local and cloud storage by going to settings and toggling the switch to “off”. If you do turn off this functionality none of your ECG data will be stored either on the cloud or on your device; AliveCor will be unable to retrieve this data and will not send out reports, for example monthly reports under premium services.

This Privacy Policy May Not Apply to All EEA Users. This Privacy Policy does not apply to EEA users using the Services under direction from a physician and where the physician and the patient have an agreement between them covering the use of the Services; in such a case the physician or his/her institution controls data collected from/by KardiaMobile and the App, and the physician’s or his/her institution’s privacy policy will apply, not this Privacy Policy.

How May I Exercise My Individual Rights? AliveCor users whose data is governed by this Privacy Policy located worldwide may access and update their personal information as follows:

Please note that AliveCor may request additional information from you to verify your identity before we disclose any personal or account information.


Contact Us

If you have questions about our privacy practices, please contact us at privacy@alivecor.com.

AliveCor, Inc.
Attn. Privacy
444 Castro St #600
Mountain View, CA 94041

If you are an EEA customer and are unable to reach AliveCor at the contact information provided above regarding your issue, you have the right to contact your local Data Protection Authority.


Changes to this Policy

This Policy is current as of the Effective Date set forth above. We may change this Policy from time to time, so please be sure to check back periodically. We will post any changes to this Policy on our Service. If we make any changes to this Policy that materially affect our practices with regard to the personal information we have previously collected from you, we will endeavor to provide you with notice in advance of such change.