PRIVACY NOTICE

At AliveCor your privacy is important to us. Our Privacy Notice describes the information we collect, how we collect information, and the reasons we collect information. This Privacy Notice also describes the choices you have with the information we collect, including how you can manage, update, or request to delete information.

Please take a moment to review this Privacy Notice. You may scroll through this Privacy Notice or use the links below to navigate to specific sections. It is important that you understand this Privacy Notice. By using our website, mobile app, software, and/or services, you are agreeing to the terms of this Privacy Notice. If you have any questions or concerns about this Privacy Notice, you may Contact Us at any time.

For certain NHS and EEA users: Neither this Privacy Notice nor the GDPR Privacy Addendum apply to NHS-patients or other users using the Services under the direction of a healthcare provider, where in such case the healthcare provider or its employer is the Data Controller (e.g., an NHS organisation in the UK, any other government healthcare system, a public or private hospital or a physician’s office) and their privacy notice will apply, not this Privacy Notice.

Table of Contents

I. Who is AliveCor?

II. Key Terms & Definitions and Our Privacy Notice

When does our Privacy Notice apply?

When does our Privacy Notice not apply?

Our Privacy Notice and Terms of Service.

III. Personal Data

What is Personal Data?

What types of Personal Data do we collect?

How do we collect your Personal Data?

How do we use your Personal Data?

How do we share your Personal Data?

Your choices about how we share your Personal Data.

How do I access and correct my Personal Data?

IV. Who may use the Services?

V. Children's Privacy

VI. Does AliveCor respond to Do Not Track signals?

VII. Data Security

[VIII. Jurisdiction-Specific Privacy Rights](#viii jurisdiction-specific-privacy-rights)

IX. Changes to our Privacy Notice

X. Contact Us

I. Who is AliveCor?

Our mission is to save lives and transform cardiology by delivering intelligent, highly-personalized heart data to clinicians and patients anytime, anywhere.

AliveCor is not a medical group or a health care provider. AliveCor provides its users with the ability to obtain a telemedicine consultation provided by independent medical practitioners including, but not limited to, Florida Cardiac Health Medical Group, P.A. d/b/a Cardiac Health Medical Group and members of its Affiliated Covered Entity (collectively “Cardiac Health Medical Group”), an independent medical group with a network of United States based health care providers (each, a “Provider”). Cardiac Health Medical Group (or your own medical provider if you do not use a Cardiac Health Medical Group Provider) is responsible for providing you with a Notice of Privacy Practices describing its collection and use of your health information, not AliveCor.

II. Key Terms & Definitions and Our Privacy Notice

It is helpful to start by explaining some of our key terms and definitions used in this Privacy Notice.

Key Term Definition
“Affiliated Covered Entities” Is a group of independent medical practices providing licensed cardiac medical services exclusively to users and/or members of Kardia, Kardia+ and KardiaComplete services.
our “App(s)” Kardia™, KardiaComplete, KardiaStation, and/or KardiaPro
our “Devices” KardiaMobile®; KardiaMobile 6L; or KardiaMobile Card
Personal Information Any information relating to an identified or identifiable individual and any information listed here.
Personal Data Any information relating to an identified or identifiable individual and any information listed here.
Privacy Notice This Privacy Notice.
our “Services” Our Website, our App, our Software and any services provided through our Website, our App, or our Software. Services also includes membership in the KardiaCare, KardiaCare+ or KardiaComplete services.
our “Software” KardiaPro, our software
our “Terms of Service” Our terms of service located here.
our “Website(s)” Our websites, including:
AliveCor, we, us, or our AliveCor, Inc., Cardiolabs, Inc (d/b/a AliveCor Labs), AliveCor Labs, LLC, and AliveCor Services, LLC (collectively, “AliveCor”).

When does our Privacy Notice apply?

This Privacy Notice describes the types of information we may collect from you when:

When does our Privacy Notice not apply?

This Privacy Notice does not apply to information collected by any other website operated either by us or by a third party, unless the website is listed above or links to this Privacy Notice. It also does not apply to any website that we may provide a link to or that is accessible from our Services.

Our Privacy Notice and Terms of Service.

This Privacy Notice is incorporated into our Terms of Service, which also apply when you use our Services.

III. Personal Data

What is Personal Data?

Personal data is information from and about you that may be able to personally identify you. We treat any information that may identify you as personal data. For example, your name and e-mail address are personal data.

What types of Personal Data do we collect?

We may collect and use the following personal data (hereinafter, collectively referred to as “Personal Data”):

Categories of Personal Data Specific Types of Personal Data Collected
Personal Identifiers a real name, birth date, e-mail address, shipping address, or Patient ID.
Information that identifies, relates to, describes, or is capable of being associated with a particular individual name, username or online identifier, physical characteristics or description, shipping address, telephone number, credit card number, debit card number, or any other financial information, health or medical information, weight, body mass index (BMI), whether you are a smoker or non-smoker, medical conditions, family medical history, medications currently taking or prescribed, electrocardiogram (“ECG” or “EKG”) measurement data, average heart rate, location on your body where a EKG was taken (e.g. finger tips, chest, limbs, etc.), heart rate, step count, distance traveled, glucose and oxygen saturation levels, active and resting energy levels, sleep analysis, blood pressure readings, workout history, your activity levels, and accelerometer data.
Characteristics of protected classifications under California or federal law. Race, Color, Age, National origin, or Disability
Biometric information Photos, video, and voice
Internet or other electronic network activity information IP address, device mode, device ID, OS version, device language, operating system, browser type, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement.
Geolocation data Physical location or movements, local time, and local time zone.
User Generated Content You may use your mobile device to add notes, tags, or voice memos to EKG recording you make with our Devices. For example, you may add a note to an EKG recording to describe how you were feeling at the time of the recording, what you were doing, or your diet related to specific health conditions. We will automatically transcribe any voice memos and include them with the EKG recordings.

How do we collect your Personal Data?

We collect most of this Personal Data directly from you. For example, when you set up an account through the App or sign up for Services, we may speak to you by phone, text message, and e-mail. Additionally, we will collect information from you when you visit our Website or App and fill out forms, use our Software or our Devices, or purchase or use our Services.

We may also collect Personal Data in the following ways:

We will also collect information automatically as you navigate through our Website and App. We use the following technologies to automatically collect data:

How do we use your Personal Data?

We may use your Personal Data for the following purposes:

How do we share your Personal Data?

We do not share, sell, or otherwise disclose your Personal Data for purposes other than those outlined in this Privacy Notice. However, we may disclose Personal Data that we collect or you provide as described in this Privacy Notice for the following reasonsPersonal DataPersonal Data:

Your choices about how we share your Personal Data.

This section of our Privacy Notice provides details and explains how to exercise your choices. We offer you choices on how you can opt out of our use of tracking technology, disclosure of your Personal Data for our advertising to you, and other targeted advertising. We do not control the collection and use of your information collected by third parties. These third parties may aggregate the information they collect with information from their other customers for their own purposes. You can opt out of third parties collecting your Personal Data for targeted advertising purposes in the United States by visiting the National Advertising Initiative's (NAI) opt-out page and the Digital Advertising Alliance's (DAA) opt-out page. Each type of web browser provides ways to restrict and delete cookies. Browser manufacturers provide resources to help you with managing cookies. Please see below for more information.

For other browsers, please consult the documentation that your browser manufacturer provides.

If you do not wish to have your e-mail address used by AliveCor to promote our own products and services, you can opt-out at any time by clicking the unsubscribe link at the bottom of any e-mail or other marketing communications you receive from us or logging onto your Account Preferences page. This opt out does not apply to information provided to AliveCor as a result of a product purchase, or your use of our Services. You may have other options with respect to marketing and communication preferences through our Services.

You may also see certain ads on other websites because we participate in advertising networks. Ad networks allow us to target our messaging to users through demographic, interest-based, and contextual means. These networks track your online activities over time by collecting information through automated means, including through the use of cookies, web server logs, and web beacons. The networks use this information to show you advertisements that may be tailored to your individual interests.

How do I access, correct, or delete my Personal Data?

You can review and change your Personal Data by logging into our Services and visiting either the “About You” or “Health Details” sections of our Services. You may also notify us through the Contact Information below of any changes or errors in any Personal Data we have about you to ensure that it is complete, accurate, and as current as possible or to delete your account. We cannot delete your personal data except by also deleting your account with us. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.

The jurisdiction in which you are a resident or are located may provide you with additional rights and choices regarding your Personal Data. Please see Section VIII, Jurisdiction-Specific Privacy Rights, below, for more Information.

IV. Who may use the Services?

This Privacy Notice applies to all personal uses of our Services globally and you should not use the Services if you do not agree to the Privacy Notice. Privacy NoticePrivacy NoticePrivacy NoticeIf you are located in the United States or a country outside the EEA or Brazil, your information is stored in the United States, and by using or downloading the Service you agree that your Personal Data, including any information about your health that you provide directly to us or that we collect through your use of the Service, may be transferred to and stored in the United States. If you are a Brazilian user, we store your information in the European Union where all such information is processed in compliance with GDPR.

V. Children's Privacy

Our Services are not intended for children under 18 years of age. We do not knowingly collect or sell Personal Data from children under the age of 18. If you are under the age of 18, do not use or provide any information on or in these Services or through any of its features. If we learn we have collected or received Personal Data from a child under the age of 18 without verification of parental consent, we will delete it. If you are the parent or guardian of a child under 18 years of age whom you believe might have provided use with their Personal Data, you may Contact Us to request the Personal Data be deleted.

VI. Does AliveCor respond to Do Not Track signals?

Some web browsers have a “Do Not Track” feature. This feature lets you tell websites you visit that you do not want to have your online activity tracked. These features are not yet uniform across browsers. Our Website and App are not currently set up to respond to those signals.

VII. Data Security

We have taken steps and implemented administrative, technical, and physical safeguards designed to protect against the risk of accidental, intentional, unlawful, or unauthorized access, alteration, destruction, disclosure, or use. The Internet is not 100% secure and we cannot guarantee the security of information transmitted through the Internet. Where you have been given or you have chosen a password, it is your responsibility to keep this password confidential. The sharing and disclosing of information via the Internet is not completely secure. We strive to use best practices and industry standard security measures and tools (e.g., SOC2 and ISO 27001 certifications) to protect your data. However, we cannot guarantee the security of Personal Data transmitted to, on, or through our Services. Any transmission of Personal Data is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on our Website, our App, our Software, our Device, in your operating system, or mobile device. For more information, see our Security page.

VIII. Jurisdiction-Specific Privacy Rights

The law in some jurisdictions may provide you with additional rights regarding our use of Personal Data. To learn more about any additional rights that may be applicable to you as a resident of one of these jurisdictions, please see the privacy addendum for your jurisdiction that is attached to this Privacy Notice.

Your GDPR Privacy Rights

If you are a resident of the European Economic Area you have the additional rights described in our GDPR Privacy Addendum.

Your California Privacy Rights

If you are a resident of California, you have the additional rights described in the California Privacy Addendum.

Your Colorado Privacy Rights

If you are a resident of Colorado, you have the additional rights described in the Colorado Privacy Addendum.

Your Nevada Privacy Rights

If you are a resident of Nevada, you have the additional rights described in the Nevada Privacy Addendum.

Your Utah Privacy Rights

If you are a resident of Utah, you have the additional rights described in the Utah Privacy Addendum.

Your Virginia Privacy Rights

If you are a resident of Virginia, you have the additional rights described in the Virginia Privacy Addendum.

IX. Changes to our Privacy Notice

We may update our Privacy Notice periodically to reflect changes in our privacy practices, laws, and best practices. We will post any changes we make to our Privacy Notice on this page with a notice that the Privacy Notice has been updated on our Website's homepage or our App's home screen. If we make material changes to our practices with regards to the Personal Data we collect from you, we will notify you by e-mail to the e-mail address specified in your account and/or through a notice on the Website's home page or the App's home screen. The date this Privacy Notice was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable e-mail address for you, and for periodically accessing the App or visiting our Website and reviewing this Privacy Notice to check for any changes.

X. Contact Us

If you have any questions, concerns, complaints or suggestions regarding our Privacy Notice or otherwise need to contact us, you may contact us at the contact information below or through the “Contact Us” page on or in our Services.

How to Contact Us:

AliveCor, Inc.
Attn: Privacy
189 Bernardo St
Mountain View, CA 94043
Telephone: 1-(855) 338-8800
E-mail: privacy@AliveCor.com

For Indian Users
AliveCor India Private Limited
05-155, WeWork Management Private Ltd, DLF FORUM,
DLF Cyber City, Phase-III, Gurugram Gurgaon HR
122002 IN
E-mail: Privacy@AliveCor.com

For Korean Users
AliveCor Korea Inc.,
(Cheongdam-don) 37, Dosan-daero 81-gil,
Gangnam-gu, Seoul KR
E-mail: Privacy@AliveCor.com

GDPR Privacy Addendum

Last modified: [02/13/2023]

Neither this Privacy Notice nor this GDPR Privacy Addendum apply to NHS-patients or other users using the Services under the direction of a healthcare provider, where in such case the healthcare provider’s or its employer’s (e.g., NHS in the UK, any other government healthcare system, a public or private hospital or a physician’s office) privacy notice will apply, not this Privacy Notice.

I. Introduction

This GDPR Privacy Addendum (the “GDPR Privacy Addendum”) supplements the information contained in our Privacy Notice (our “Privacy Notice”) and applies solely to the users of our mobile apps (e.g., Kardia) for collecting and analyzing ECG data that may also include other related functionalities, software, and/or services who are located in the European Economic Area, the United Kingdom, and Switzerland. We adopt this GDPR Privacy Addendum to comply with the European Union’s and the UK’s General Data Protection Regulation, and any laws implementing the foregoing by any member states of the European Economic Area, the United Kingdom (including the UK Data Protection Act and the UK GDPR), and/or Switzerland (collectively, the “GDPR”). Unless otherwise defined in this GDPR Privacy Addendum, any terms defined in the GDPR or our Privacy Notice have the same meaning when used in this GDPR Privacy Addendum. When this GDPR Privacy Addendum is applicable to you, it takes precedence over anything contradictory in our Privacy Notice.

II. Data Controller, Data Protection Officer, and Representative

For those for whom the Privacy Notice and this Addendum do apply, AliveCor is the Data Controller of the Personal Data you provide on the Services. If you are an EEA or a UK user, your Personal Data you provide on the Service is stored within the EEA.

AliveCor has appointed a Data Protection Officer (Bill Jacobs) in compliance with the GDPR. At this time, AliveCor is not required to appoint a Data Protection Officer or representative in the United Kingdom, and has elected not to do so. AliveCor and its subsidiary, AliveCor, LTD, and its Data Protection Officer may be contacted in any manner set forth below in Contact Information.

III. Information We Collect About You and How We Collect It

The Personal Data we collect and the ways in which we collect it are described in our Privacy Notice.

The Personal Data we collect from you is required to enter into an agreement for services with AliveCor, for AliveCor to provide the product and services under that agreement, and to provide you with our products and services. If you refuse to provide such Personal Data or withdraw your consent to our processing of Personal Data (when appropriate), then in some cases we may not be able to enter into the contract or fulfill our obligations to you under it.

IV. Lawful Basis for Processing Your Personal Data

The processing of your Personal Data is lawful only if it is permitted under the GDPR.

Under Art 6(1)[a] and Art 9 (2)[a] of applicable GDPR regulations (UK or EU), we rely on your consent as a lawful basis to process your Personal Data for the following purposes:

By using our Services, you consent to our collection, use, and sharing of your Personal Data as described in our Privacy Notice and this GDPR Privacy Addendum. If you do not consent to the terms of our Privacy Notice and this GDPR Privacy Addendum, please do not use our Services. You may terminate Your participation by sending directions to any of the contacts set forth below in Contact Information.

We also process Personal Data based on our contractual obligations to provide you the Services as described in How do we share your Personal Data?, including:

AliveCor may also process Personal Data as Required by Law or to protect your vital interests or those of another person. Accordingly, we may also process your Personal Data when we are required or permitted to by law; to comply with government inspections, audits, and other valid requests from government or other public authorities; to respond to legal process such as subpoenas; or as necessary for us to protect our interests or otherwise pursue our legal rights and remedies (for instance, when necessary to prevent or detect fraud, attacks against our network, or other criminal and tortious activities), defend litigation, and manage complaints or claims. We will process your Personal Data as necessary for our legitimate interests. Our legitimate interests are balanced against your rights and freedoms and we do not process your Personal Data if your rights and freedoms outweigh our legitimate interests. Our legitimate interests are to: facilitate communication between AliveCor and you; detect and correct bugs and to improve our Services; safeguard our IT infrastructure and intellectual property; detect and prevent fraud and other crime; develop our product and services.

V. Automated Decision Making

Our processing of Personal Data may include automated decision making, including profiling, which may produce a legal effect concerning you or similarly significantly affect you. The algorithms used for our automated decision making process classifies and categorizes your health (i.e., the instant determinations provided (e.g., normal sinus rhythm, bradycardia, tachycardia, atrial fibrillation or unclassified)), based on data collected by the Devices and Personal Data collected by the Services.

VI. How We Use Your Information

We use your Personal Data as described in our Privacy Notice.

VII. Disclosure of Your Information

We do not share or otherwise disclose your Personal Data for purposes other than to the entities and for the purposes described in our Privacy Notice.

VIII. Your Rights Regarding Your Information and Accessing and Correcting Your Information

The GDPR (UK and EU) provides you with certain rights with regards to our processing of your Personal Data. These rights replace the similar rights provided in our Privacy Notice or are supplemental to such rights.

IX. Data Retention Periods

AliveCor will retain your Personal Data for the entire time that you keep your account open or until you request us to delete your Personal Data (subject to above). After this period, we may retain your Personal Data for [x] years, or for any of the reasons listed below, whichever is longer:

X. Changes to This GDPR Privacy Addendum

We may change this GDPR Privacy Addendum at any time. We will post any changes we make to this GDPR Privacy Addendum on this page with a notice that this GDPR Privacy Addendum has been updated on our Website's homepage or our App's home screen.  If we make material changes to our practices with regards to the Personal Data we collect from you, we will notify you by e-mail to the e-mail address specified in your account and/or through a notice on the App's home screen. The date this GDPR Privacy Addendum was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable e-mail address for you, and for periodically accessing the App or reviewing this GDPR Privacy Addendum to check for any changes.

XI. Contact Information

If you have any questions, concerns, complaints, or suggestions regarding our Privacy Notice or this GDPR Privacy Addendum, have any requests related to your Personal Data described in the Privacy Notice or this GDPR Privacy Addendum, or otherwise need to contact us, you may contact us at the contact information below or through the “Contact Us” page on or in our App and/or Software.

To Contact Our Representative in the EU

AliveCor, LTD
Herschel House
58 Herschel Street
Slough SL1 1PG
E-mailPrivacy@AliveCor.com

To Contact Our Data Protection Officer

Attn: Bill Jacobs
189 N. Bernardo Ave. Ste. 100
Mountain View, CA
94043
E-mail: privacy@alivecor.com