Privacy Policy
Last Updated: February 10, 2022.
Effective: This Privacy Policy is effective as of the date of your first use of the Services.
PLEASE READ THIS POLICY CAREFULLY BEFORE USING THE SERVICES.
You must be 18 years of age or older to use the Services. It is expressly prohibited for minors under the age of 18 to create or use an Anura account.
Your privacy is important to us, and we are committed to protecting it through our compliance with this privacy policy (“Policy”). The information provided below describes how and why we process your personal data, which you share with us and which we collect when you access or use our services, Anura mobile application (“Anura”) and/or our website (“Site”) located at www.anura.ai (such services, Anura and the Site are collectively referred to as the “Services”). Personal data (hereinafter “Personal Data”) means any information relating to an identified or identifiable natural person. Unless defined where used, capitalized terms used herein shall have the meanings given in the Terms of Use.
The information provided does not apply to third-party online websites, pages or services that can be accessed via hyperlinks through the Services. Clicking on those hyperlinks may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy policies. When you leave our Services, we encourage you to read the privacy policy of every website or mobile application you visit.
If you are a resident of the European Economic Area (including residents of Switzerland and United Kingdom), please see our “GDPR Compliance” section below which details how we process your personal data in accordance with the General Data Protection Regulation (“GDPR”).
WHO WE ARE
Nuralogix Corporation (hereinafter: “Nuralogix”, “we”, “us” or “our” and terms of similar meaning) is the data controller (“Controller”) responsible for the use and processing of your Personal Data as described in this Policy.
We have appointed a Data Protection Officer (“DPO”) who is responsible for overseeing our privacy practices and questions in relation to this Policy. If you have any questions about this Policy, including any requests to exercise your legal rights (as detailed below), please contact the DPO using the following email address: privacy@nuralogix.ai
WHAT INFORMATION WE PROCESS
Whenever you access or use our Services, we may process (e.g., collect, use, store, transfer, etc.) different kinds of personal data about you, which we will process in accordance with this Policy, and which have been categorized as follows:
Category of Data Subject |
Types of Personal Data Processed |
Description/Purpose of Processing |
Client Application Authorization (to utilize DeepAffex services) |
License Management |
NOTE: The device token is NOT bound with any user- information nor with any form of device-type attributes such as IMEA, serial-number, mac-address. An assigned token is used only to authorize/permit application transactions with the DeepAffex service (API). |
|
|
Processed at point of application registration/initiation of service use |
Platform Information |
Application Analytics |
Collected and processed at point of application registration/initiation of service use |
Measurement Subjects |
Identification and Contact Data |
Collected and processed at point of application registration/initiation of service use and measurement requests. |
Measurement Subjects |
Identification and Contact Data |
B2B format-free/unstructured tag that may be generated and assigned by the Customer/Partner application, no interpretation or meaning attached |
Authorized Customer Main Party Dedicated Portal (Dashboard) Users |
Identification and Contact Data |
Associated with the Customer Main Party Dedicated Portal for access, verification, and password resets. |
Measurement Subjects |
Personal Demographics |
To achieve more accurate Measurement results, the processing and analysis may also require or involve additional Personal Data including, but not limited to, the following: |
|
|
|
Measurement Subjects |
Biometric Data |
When the service is in use, we capture, but do not store, images and video through supported mobile device cameras for the purpose of extracting and analyzing the following:
|
Measurement Subjects |
Wellness Data and Measurements |
Biometric Data is used to provide heart rate, breathing rate, blood pressure, heart rate variability, cardiac workload, stress index, body mass index, cardiovascular disease risk, heart attack risk, stroke risk, general wellness score, or other similar derived data. This data is the output data generated from providing the Services as opposed to what we collect. |
Measurement Subjects |
Personal Habits and Medical History |
To achieve more accurate Measurement results, the processing and analysis may also require or involve additional Personal Data including, but not limited to, asking if you are any or all of the following:
|
Measurement Subjects |
Log Data |
When our Services are used, our servers automatically record certain information about how a person uses our Services whether by log files, and scripts, including without limitation IP address, configuration information, information about interaction with our Services, device information, and the date, time and/or location that a measurement was taken. |
HOW WE COLLECT YOUR DATA
We use different methods to collect data from and about you including through:
Direct interactions: You may give us your personal data (sensitive data included) by filling in forms or by corresponding with us by post, email or otherwise. This includes personal data you provide when you:
- use our products or Services (Use Information)
When you use our Services, we may receive or collect information or data about you or relating to you such as product reviews, comments, your public profile, photos and videos.
- create an account on our App (Log-in Information)
Depending on the jurisdiction in which you are based, you may be required to provide log- in information to use our Services and create an account to access the full features of our Services which may include your email address, name, nickname/username, phone number (Identification Data) and information related to your wellness and lifestyle (Personal Habits and Medical History).
- give us feedback or contact us (Customer Support Information)
Any information that you provide to our customer support team from the correspondence that you send to us, any conversations you have with us and any feedback that you give us.
Third parties: We may receive personal data about you from third parties.
Cookies
In our Anura mobile app we only use so-called “technical cookies”, which allow us to recognize you as a user with each access. Such data is not passed on to third parties.
On the website, we also use Google Analytics cookies to help us to improve our website by collecting and reporting information on how you use it. The cookies collect information in a way that does not directly identify anyone.
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of the website may become inaccessible or not function properly.
HOW WE USE YOUR PERSONAL DATA
We use the Personal Data you provide or which we collect mainly for the following purposes. We have included below a list of all the ways in which we use your personal data and the lawful bases (where applicable) we rely on to do so.
PROVIDE THE SERVICE
- Purposes: provide you with our Services and create an account as described in our Terms of Use to produce the Measurements and Wellness Data (i.e. the creation of wellness measurements based on the extraction and analysis of your facial blood flow data) and provide our customer support to you.
- Types of Data: Identification Data, Personal Characteristics, Biometric Data (Sensitive Data), Personal Habits and Medical History (Sensitive Data), Location Data, Log Data, Wellness Data and Measurements
- Retention Period: Your Personal Data is stored for this purpose for 30 days after your user account is deleted or the termination of the service provision (or for a further time where legally required).
ANALYSE, DEVELOP, AND IMPROVE TECHNICAL FUNCTIONALITIES, AND ENSURE THE SECURITY OF OUR SERVICES
- Purposes: We continuously strive to provide the best experience possible. We therefore may use your Personal Data to analyze, develop, and improve technical functionalities and ensure the security of our Services.
- Types of Data: Personal Characteristics, Biometric Data (Sensitive Data), Location Information and Log Data.
- Retention Period: Your Personal Data is stored for this purpose until your user account is deleted or such period as is necessary to anonymize the data, test features or functionality and deploy patches and other bug fixes.
DIRECT MARKETING, COMMERCIAL COMMUNICATIONS
- Purposes: The processing of Personal Data collected on the website for “direct marketing, commercial communications” is subject to your expressed and specific consent (provided on the website). We may process your Identification data, for marketing purposes, by sending newsletters, commercial communications and / or advertising material, on products or services offered by us. Personal data collected on the mobile App is not processed for this purpose.
- Types of Data: Identification and Contact Data
- Retention Period: Your Personal Data is stored for this purpose for 30 days after your user account is deleted, the consent is withdrawn or the termination of the service provision (or for a further time period where legally required).
OTHER PURPOSES
Safety and Security
If necessary, we may use your Personal Data to promote the safety and security of our Services and our users. We may use your Personal Data to monitor operations, authenticate users, detect and protect against fraud and other criminal activity and enforce our Terms of Use and other policies. We will rely on our legitimate interests when processing Personal Data in detecting and preventing fraud and illegal conduct or if necessary for complying with a legal obligation to which we are subject.
Manage and Defend Legal Claims
If necessary, we may use your Personal Data to manage and defend legal claims (e.g., in connection with a dispute or a court proceeding). We will in such case process the Personal Data collected which is necessary to manage and defend the legal claim in question. The processing is based on our legitimate interest of managing and defending legal claims. Your Personal Data is stored for this purpose for such a period as is necessary to manage or defend the legal claim.
For this purpose, we may also share certain information with other parties, please see below.
Fulfill Legal Obligations
Finally, we may use your Personal Data to fulfil legal obligations that we have (e.g., accounting requirements or obligations under data protection laws). We will in such case process the Personal Data collected which is necessary to fulfill the legal obligation in question. Your Personal Data is stored for such a period as is necessary to fulfill respective legal obligations.
For this purpose, we may share your Personal Data with other parties, see below.
We will only use your Personal Data for the reasons we have set above. If we need to use your Personal Data for any other reason, we will let you know and tell you the reason along with the relevant lawful basis, unless the law prevents us from doing so.
HOW WE SHARE YOUR PERSONAL DATA
In general, we do not disclose the Personal Data about you to third parties without your consent or otherwise as specified in this Policy. We may disclose or share your Personal Data in the following circumstances:
Sharing of Personal Data by Nuralogix
We may disclose or share your Personal Data with third parties only in the ways described in this Policy, including as follows:
- In certain situations, NuraLogix may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. NuraLogix may disclose your Personal Data (i) to any governmental authority as part of an investigation to determine our compliance with any applicable law, rule, or regulation (including privacy laws, rules, and regulations), (ii) in response to a court order, subpoena, discovery request, or other lawful judicial or administrative proceeding, (iii) as otherwise required or permitted under any applicable law, rule, or regulation, (iv) in good faith, to protect or defend the rights or property of NuraLogix and other users, and (e) if NuraLogix is involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our Site of any change in ownership or uses of your Personal Data, as well as any choices you may have regarding your Personal Data;
- We may use third party service providers to provide certain data processing services for us (acting as our authorized data processors) with whom we have a data protection agreement in place. When acting as our authorized data processors, they are required to only process data in accordance with our instructions, in line with this Policy, and are subject to appropriate confidentiality and security obligations. Examples of authorized data processors could include Amazon Web Services.
- We may share anonymous, aggregate, or generic data with third parties (such as our partners, advertisers, industry bodies, the media and/or the general public) for example, in public reports about stress or to partners under agreement with us. However, in these situations we do not disclose any information that could be used to identify you personally.
Sharing your Information
Our Services allow you to share your Measurements in various forms with others. For example:
- You can share a link and/or image which will allow the recipient to access your Measurement(s).
- Your Personal Data could be also shared by you if you and other users are using and logging onto the family or enterprise version of Anura (where available) whereby certain user(s) or the administrator user of such version of Anura (subject to specific settings made and/or availability of relevant functions) would have access to the Measurement results or information of the other users.
- Any Personal Data shared by you in the above circumstances will be shared by you with your consent. Please consider carefully whether you desire to share your Personal Data as described above.
HOW WE PROTECT YOUR PERSONAL DATA
We keep your data safe adopting the best practices and highest standards in terms of security. All required technical and organizational security measures have been adopted.
We take various steps to protect your Personal Data from unauthorized access, use or modification and unlawful destruction and disclosure, for example:
- we adopt encryption technology (such as SSL) to transfer and store your Personal Data.
- we limit the access to your Personal Data on a strict need-to-know basis.
- we put in place physical, electronic, and procedural safeguards in line with industry standards.
Please be aware that, despite our efforts, we do not warrant or guarantee that unauthorized access will never occur as no method of transmitting or storing information is completely secure.
DATA RETENTION AND STORAGE
Data Retention
In principle, unless otherwise stated, your Personal Data will only be stored until the purpose of the collection and storage no longer applies. In accordance with your consent, data may also be stored for longer, if you do not withdraw your consent. After this period, we may keep your personal data for a further time period to:
(a) communicate with you about any questions or complaints you may have after you have stopped being a user of our Services; or (b) to comply with the rules on accounting, reporting or any other law.
Furthermore, data may be stored if this has been provided for by the competent legislator in regulations, laws or other regulations to which we are subject. Data will also be blocked or deleted if a storage period prescribed by the aforementioned standards expires, unless there is a need to continue storing the data for the purpose of concluding or fulfilling a contract.
In the event of termination – for whatever reason – of the agreement between the user and us we shall keep all content, information and (personal) data uploaded by the user available for retrieval by the user for a further 60 days after termination. After expiry of this period, the aforementioned content will be irrevocably deleted or anonymized in accordance with data protection regulations.
To protect your privacy, certain information that we collect which can identify you as an individual is not stored. In particular, we do not store your facial image or video recordings neither on the device on which Anura is installed nor on the cloud.
We will retain your Personal Data for as long as is reasonably necessary for the various purposes mentioned above or to otherwise comply with any applicable laws and regulations concerning the mandatory retention of specific types of Personal Data.
We will retain your data for as long as your account is active or as needed to provide you Services. We will retain and use your data as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements; this retention period may extend past the point at which you close your account.
In certain circumstances, we may aggregate your Personal Data (so that it will no longer identify you) for research, analytical or statistical purposes, in which case we may use this information indefinitely without further notice to you.
If you would like further information on how long we keep your Personal Data, please contact us using the details set out at the end of this Policy.
Storage Location
All Personal Data processed and collected to provide our Services outside of the device in which Anura is installed is stored with cloud service providers managed by us.
You can ask us for more information about where we may transfer or store your Personal Data and how we will take steps to ensure your Personal Data is protected by using the contact details at the end of this Policy.
YOUR RIGHTS
Your access to certain rights depends on the country in which you are based, and you may have certain rights in relation to the use of your Personal Data. If you wish to exercise your rights, please contact us at: privacy@nuralogix.ai
You have the right to:
TO BE INFORMED
You have the right to be provided with clear, transparent, and easily understandable information about how we use your Personal Data, and your rights. This is what we are doing, providing you with the information in this Privacy Policy.
TO ACCESS YOUR PERSONAL DATA
You have the right to request access to your Personal Data and request a copy of your Personal Data that we store. If you have created a user account, you can view certain information directly from our Services on your user interface or by sending us a specific request.
TO UPDATE YOUR PERSONAL DATA
You have the right to request that Personal Data that is incorrect or incomplete is corrected or completed. If you have created a user account, you can update certain information directly in your account or by sending us a specific request.
TO WITHDRAW CONSENT
If we rely on your consent to the use of your Personal Data you have the right to, at any time, withdraw your consent. The consent withdrawal does not affect the legality of the processing carried out previously based on the consent.
TO DELETE YOUR PERSONAL DATA (RIGHT TO BE FORGOTTEN)
You can at any time request that your user account is deleted. Moreover, under certain circumstances, you have the right to request that your Personal Data shall be deleted.
Please note that if you request us to remove your Personal Data, you may not be able to use our Services.
We may, however, still need to keep your Personal Data if we are obligated to keep certain data to fulfill legal obligations or to manage or defend legal claims.
TO RESTRICT THE USE OF YOUR PERSONAL DATA
You have, under certain circumstances, the right to request that the use of your Personal Data is restricted. If you have requested restriction of the use of your Personal Data, please note that you cannot use the platform during the time that the use of your Personal Data is restricted.
TO OBJECT TO THE USE OF YOUR PERSONAL DATA
Certain use of your Personal Data is based on our or others’ legitimate interest. You may have the right to object to the use of your Personal Data based on a legitimate interest for reasons which concerns your particular situation. In such a situation, we will stop using your Personal Data where the use is based on a legitimate interest, unless we can show that the interest overrides your privacy interest or that the use of your Personal Data is necessary in order to manage or defend legal claims.
TO NOT TO BE SUBJECT TO A DECISION BASED SOLELY ON AUTOMATED DECISION-MAKING
You may have the right not to be subject to such type of automated decision-making about you, unless: (a) you gave us your explicit consent to use your Personal Data to make our decision; (b) we are allowed by law to make our decision; or (c) our automated decision was necessary to enable us to enter a contract with you.
TO TRANSFER YOUR PERSONAL DATA (DATA PORTABILITY)
You have the right to obtain a copy of certain information that you have provided to us in a structured machine-readable format which allows you to transfer the data to another recipient.
Responding to Your Requests
Subject to the applicable law, you are entitled to submit the above requests by contacting us at
We will respond to all requests that we receive from users in accordance with applicable data protection laws. Subject to applicable laws, we reserve the right to refuse the request if it is manifestly unfounded or manifestly excessive. In these scenarios, we will inform you of the reasons why and your corresponding rights.
We may ask you to provide proof of your identity before we can answer your requests.
In certain situations, depending on the jurisdiction in which you are based, we may not be able to respond to your request.
GDPR COMPLIANCE
As our Company is based in Canada and processes Personal Data of data subjects who are in the European Economic Area, the General Data Protection Regulation (“GDPR”) applies to our processing of Personal Data. Accordingly, this Privacy Policy also provides you with the additional information as set out in the GDPR. Our handling of Personal Data of data subjects who are in Europe is in compliance with the GDPR.
EU Representative
As we are based outside of the EU, we have appointed the following EU Representative to act on our behalf when we undertake data processing activities to which the GDPR applies:
Chino Srls
Via Segantini 28, Rovereto (TN) 38068
Italy
Email: nuralogix-eurepresentative@chino.io
Lawful Basis
We will only use your personal data where we have a valid lawful basis to do so in accordance with the GDPR. Where we mention our “legitimate interests”, this is the lawful basis we rely on when we feel that it is necessary to use your Personal Data for a reason which is in our and/or your interests and which does not unfairly affect your rights over your Personal Data.
Providing the Service
The processing of Personal Data is based on Art. 6. (1) (a) GDPR your consent and Art. 6. (1) (b) GDPR the necessity of the processing for the performance of the contract. The legal basis for the processing of sensitive data (health data) is the Art. 9 (2) (a) GDPR, i.e., your explicit consent.
Analyse, develop and improve technical functionalities, and ensure the security of our services
The processing of Personal Data is based on our legitimate interest in developing/improving, ensuring the technical functionality and the security of our Services (art. 6 (1) (f) GDPR). Special categories of Personal Data (sensitive personal data) may be processed for statistical and research purposes focused on analyzing, developing and improving technical functionalities, and ensuring the security of our services (art. 9 (2) (j) GDPR in accordance with the appropriate safeguards (such as: pseudonymization or anonymization – art. 89
GDPR).
Direct Marketing, Commercial Communications
The processing of Personal Data collected on the website for “direct marketing, commercial communications” is based on your consent (Art. 6. (1) (a) GDPR). Personal data collected on the mobile App is not processed
for this purpose.
Storing your Personal Data
All Personal Data of European data subjects is stored in cloud service providers located in Germany. If we do transfer or store your Personal Data outside of the EEA, we will ensure we have put adequate measures in place to protect your Personal Data to an equivalent data protection standard as in the EEA.
Right to lodge a complaint with the competent EEA supervisory authority
If you are in the EEA, as a data subject, you have a right to lodge a complaint with the competent supervisory authority under the conditions provided in Article 77 GDPR or seek a remedy in the national courts if you think that your rights in relation to your personal data have been breached. However, we would be grateful if you could give us the opportunity to address your complaint in the first instance by using the contact details
provided at the end of this Policy.
UPDATES TO THIS POLICY
We may modify and revise this Policy from time to time. Any information that we collect is subject to the Privacy Policy in effect at the time such information is collected.
Any changes we make to our Privacy Policy in the future will be posted on this page, and where appropriate, notified to you by email or notifications via Anura. We therefore encourage you to review it from time to time to stay informed of how we are processing your data.
CONTACT US
If you have questions, suggestions, or concerns about this Policy, or about our use of your Personal Data,
please contact us at privacy@nuralogix.ai
Quick Links
Corporate Headquarters
NuraLogix Corporation
Toronto, Canada
250 University Avenue, Suite 209
Toronto, ON, Canada M5H 3E5
Email: info@nuralogix.ai
Phone: +1 (416) 368-6000
In the United States, this product is for Investigational Use Only. The performance characteristics of this product have not been established.
© Copyright NuraLogix Corporation
Regional Offices
North America
sales-na@nuralogix.ai
Latin America and EMEA (Europe, Middle East and Africa)
sales-emea@nuralogix.ai
APAC (Asia-Pacific)
sales-apac@nuralogix.ai
China (Mainland)
sales-china@nuralogix.ai