Privacy Policy
How we collect, use, and protect your information
1Introduction
Welcome to SKIIN! This Privacy Policy (the "Policy" or "Privacy Policy") describes how Myant Medical Corp. ("Myant", "SKIIN", "us", "our", or "we") collects, uses, and discloses information that we obtain about you and your use of the myanthealth.com website (the "Site") and the SKIIN Mobile software (the "App"), collectively "the Service", including information that we collect from the Myant SKIIN Cardiac Monitoring devices (the "SKIIN Device") that you connect to a mobile device running the App.
By using or downloading the Service, you agree that your personal information, including any information about your health that you provide directly to us or that we collect through your use of the Service, may be transferred to, stored, and handled as described in this Policy.
Myant Medical Corp. is committed to complying with the Applicable Privacy Laws as described in the next paragraph and maintaining the confidentiality of an individual's protected health information ("PHI") and personal information ("PI", or "PII") through appropriate, authorized access, uses, and disclosures. In this Policy, PI or PII means any personally identifying information about an individual, which directly or indirectly allows that individual to be identified, and any mention of "PI" or "Personal Information" shall include PHI.
As per:
- the Canadian Personal Information Protection and Electronic Documents Act ("PIPEDA");
- Quebec's Act Respecting the Protection of Personal Information in the Private Sector as amended by Law 25 (the "ARPPIPS"); and
- Ontario's Personal Health Information Protection Act ("PHIPA")
collectively the "Applicable Privacy Laws", Myant Medical Corp. must reasonably safeguard PHI and PI from any intentional or unintentional use or disclosure, and only collect, use and disclose that PI and PHI that is necessary for the purposes under the circumstances. Myant Medical Corp. must create, store, maintain, use, transmit, collect, and disseminate PI and PHI in an environment that promotes confidentiality and integrity without compromising PI and PHI.
2The Information We Collect From You and About You
We collect the following information from you and about you, but only with your informed consent, as described further below in this Policy.
The Information We Collect About You
We collect information directly from you, from devices and third-party services you connect, as well as automatically through your use of our Service.
When You Create, Update, or Add Information to Your Profile
When you register to use the Service, we collect the personal information you provide us, including your name, email address, password, gender, height, and birthdate. We also collect any additional information you choose to add to your profile, including weight, body mass index (BMI), whether you are a smoker or non-smoker, medical conditions, blood pressure, information related to medications you are taking, patient ID, sleep metrics, stress levels, activity levels, and other personal or health information.
We collect additional information from Devices you connect to your App
When you use a SKIIN Device: We collect your raw electrocardiogram (ECG) measurement data, average heart rate, and location on the body where the ECG recording was taken (e.g., body or chest). We collect additional information from your mobile device at the time of recording, including accelerometer data, local time, local time zone, and geographic location.
- You may use your mobile device to add notes, tags, or voice memos to recordings you make with any connected device. Many users use this feature to supplement ECG readings with information about their symptoms, activities, or diet related to their specific health conditions. Voice memos are automatically transcribed and included with the applicable ECG recordings. Please note that we collect information provided through notes, tags, or voice memos, including any personal or sensitive information you choose to provide through this feature.
Information Collected from Your Mobile Device: In addition to the collection described above, we collect basic information from your mobile device, including device model and OS version, device ID, device language, activities within the App and how long the App is open.
- If you choose to connect your mobile device to a compatible third-party service, such as Apple Health or Google Fit, with your permission, we collect information from your user profile including username and email address, heart rate BPM, step count and distance traveled, activity sample, glucose and oxygen saturation levels, active and resting energy levels, sleep analysis, blood pressure readings, and workout history.
When You Use A Premium Feature: When you choose to participate in a premium service, we collect additional information from you related to those services. Some premium features are paid services. When you make payments through the Service, you may need to provide your shipping address and financial account information, such as your credit card number, to our third-party service providers. We may receive transaction identifiers and summary information that does not include credit card or bank account numbers.
When You Contact Us: When you contact SKIIN directly, such as when you contact our Customer Support team, we will receive the contents of your message or any attachments you may send to us, as well as any additional information you choose to provide.
3How We Use Your Information
We use your information, including your personal information, for the following purposes:
- To provide our Service to you, to communicate with you about your use of our Service, to respond to your inquiries, and for other customer service purposes.
- To tailor the content and information that we may send or display to you, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the Service.
- For marketing and promotional purposes, to the extent permitted by law and, where required, with your consent. For example, we may use your information, such as your email address, to send you news and newsletters, special offers, and promotions, or to otherwise contact you about products or information we think may interest you. We also may use the information that we learn about you to assist us in advertising our services on third-party websites. You can opt-out of receiving marketing at any time as described below.
- To better understand how users' access and use our service, both on an aggregated and individualized basis, to improve our Service and respond to user desires and preferences, and for other analytical purposes.
- To tailor the content and information that we may send or display to you, to understand if a recorded ECG is your personal data or a guests' data, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the service.
- To administer surveys and questionnaires.
- To comply with legal obligations, as part of our general business operations, and for other business administration purposes.
- Where we believe necessary to investigate, prevent or act regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person or violations of our Terms Of Service or this Privacy Policy.
5Consent
Myant Medical Corp. will obtain consent before any collection, use or disclosure of any PII and PHI for purposes that we have identified. Individuals who sign up for a SKIIN account will provide explicit consent during account creation.
By using the Service or providing us with any PII and PHI, you consent to the transfer to, and processing, sharing and storage of your information as set forth in this Privacy Policy. Please note that other countries may have privacy and data protection regulations that are not on par with the regulations in Canada and may not provide the same level of protection.
We will always ask for your consent if we ever share or use your PII and/or PHI for a purpose other than what is in this Privacy Policy. At any point, you can withdraw your consent by contacting us at privacy@skiin.com.
6Security of Your Personal Information
Your privacy is important to Myant Medical Corp., and we enforce privacy measures to ensure that your PII and PHI is protected against unauthorized access, use and modification.
All data is protected through an AES256-bit encrypted database and data during any transfer between the database, server and mobile application is encrypted using HTTPS.
Our data exists in a private virtual cloud, hosted by Amazon Web Services (AWS). AWS provides features that help in maintaining secure data through security groups, network access control lists and flow logs. AWS has ISO 27001, ISO 27017, and ISO 27018 certifications, ensuring it meets international standards for information security management systems, security controls for cloud services and security techniques for protection of personally identifiable information.
During SKIIN account creation, a complex password (between 8 to 30 characters and a minimum of one special character or number) is required for all users. The authentication process requires email confirmation before a user can log into the application. Resetting forgotten passwords will also require email confirmation.
Only authorized individuals can access users’ PII and PHI data on secure databases, which can only be accessed through secure passwords. Employees are required to sign documentation that obliges them to protect users’ PII and PHI and will only be able to access PII and PHI to fulfill their job requirements.
We also encourage you to take your own security measures, such as the following:
- Not sharing your password with anyone else
- Remembering to log out of the Service if accessing it on someone else's personal device
- Updating your password regularly
- Having a password on your personal device
- Locking your personal device when not in use
7Security Breaches
As per the Applicable Privacy Laws, when impermissible or unauthorized access, acquisition, use, and/or disclosure of an PII or PHI handled by Myant Medical Corp. occurs, we are required to keep records and notify any involved individuals of all breaches and to report to the Privacy Commissioner of Canada and the Commission d’accès à l’information of any security breaches that pose a real risk of significant harm to any individual or the public.
8Your Rights Regarding Your Personal Information
You have certain rights regarding your PII and PHI, which are explained below. You may exercise these rights by submitting a request in writing to privacy@skiin.com.
- Right to inspect and copy: If you would like to inspect or receive a copy of your PHI that is contained in a designated record set (e.g., health and billing records), we are required to provide you access to such information within 30 days after receipt of your request (with up to a 30-day extension if required with notice). We may charge you a reasonable fee to cover duplication, mailing and other costs incurred by us in complying with your request. We may deny your request for access to your personal information as permitted by PIPEDA/PHIPA. For example, we may deny your request if we believe the disclosure will endanger your life or that of another person. Depending on the circumstances of the denial, you may have a right to have this decision reviewed.
- Right to Request Restrictions on Use and Disclosure: You have the right to request a restriction or limitation on certain uses and disclosures of your PI or health information. To request restrictions, you must make your request in writing to privacy@skiin.com. In your request, you must tell us:
- What information you wish to limit;
- Whether you wish to limit our use, disclosure, or both
- To whom you want the limits to apply - for example, if you want to prohibit disclosures for insurance payment, health care operations, for disaster relief purposes, to persons involved in your care, or to your spouse
- Right to Request Amendment: If you believe that any PI or health information, we have about you is incorrect or incomplete, you have the right to ask us to change the information for as long as Myant Medical Corp. maintains the information. To request an amendment to your health information, your request must be in writing, signed, and submitted to Myant Medical Corp. If we deny your request, we will provide you with a written explanation. You may respond with a statement of disagreement that will be maintained with your records. We will respond to your request within 60 days (with up to a 30-day extension if needed with notice).
- Right to Receive Confidential Communications: You have the right to request that we communicate with you about your health information in a confidential manner or at a specific location. For example, you may ask that we only contact you via mail to a post office box. You must submit your request in writing to Myant Medical Corp. We will not ask you the reason for your request. Your request must specify how or where you wish to be contacted. We will accommodate all reasonable requests.
- Right to Receive an Accounting of Certain Disclosures: With some exceptions, you have the right to receive an accounting of certain disclosures we have made, if any, of your health information. Your accounting request must be in writing and signed by you or your personal representative and submitted to Myant Medical Corp. Your request must specify the time in which the disclosures were made. You may receive one free accounting in any 12-month period. We will charge you for additional requests. This right only applies to disclosures for purposes other than treatment, payment or health care operations as described in this Notice. It also excludes disclosures we may have made to you, your family members or friends involved in your care. The right to receive this information is subject to certain exceptions, restrictions and limitations as allowed by PIPEDA/PHIPA.
- Right to Obtain a Copy of this Notice: You have the right to receive a paper copy of this Notice upon request, even if you have agreed to receive the Notice electronically. You may ask us to give you a copy of this Notice at any time.
- Right to Cancel Authorization to Use or Disclose: Other uses and disclosures of your health information not covered by this Notice or the laws that govern us will be made only with your written authorization. You have the right to revoke your authorization in writing at any time, and we will discontinue future uses and disclosures of your health information for the reasons covered by your authorization. We are unable to take back any disclosures that were already made with your authorization, and we are required to retain the records of the care that we provided to you.
9What Choices Do I Have Regarding Promotional Emails?
We may send periodic promotional emails to you. You may opt-out of such communications by following the opt-out instructions contained in the email. Please note that it may take up to 15 business days for us to process opt-out requests. We may still send you emails about your account or any services you have requested or received from us.
10Users Under 18
Our Service is not designed for users under 18. If we discover that a user under 18 has provided us with personal information, we will delete such information from our systems.
12Additional Information for Quebec Residents
Your Rights
Under the ARPPIPS, Quebec residents have certain additional data protection rights as mandated by the law, in addition to the rights found elsewhere in this Privacy Policy. These rights include the following.
- The right to have your personal information erased from Myant's records;
- The right to have any hyperlink from Myant or the Service that is attached to your name removed;
- The right to access your personal information and any relevant information around its use;
- The right to have a copy of your personal information given to you in an easy-to-read format so that you can transfer it to another company; and
- The right to have your personal information corrected or updated if you believe it is inaccurate or out of date.
To exercise any of these rights, please make your request to privacy@skiin.com. Please note that we may ask you to verify your identity before responding to such requests.
Protecting Your Personal Information
In addition to the measures to protect your personal information described elsewhere in this Policy, as required by the ARPPIPS we have drafted and implemented certain internal procedures and policies regarding personal information, including the following:
- A framework for the keeping and destruction of the personal information, including where we may keep anonymized data;
- Defining and describing the roles and responsibilities of the members of Myant personnel throughout the life cycle of the personal information;
- A process for dealing with individual complaints and requests for personal information and exercising of the individual’s rights under the law; and
- A management and IT policy and procedure for addressing potential data breach incidents involving personal information and PHI in the custody of Myant.
Transfer of Your Personal Information Outside Quebec
For our Quebec users, please note we transfer your personal information to organizations (including service providers) in other provinces or countries. When this happens, we do the following to safeguard your personal information:
- We will perform what the ARPPIPS calls "Privacy Impact Assessment", or "PIA" prior to the personal information leaving Quebec. If the PIA does not meet our standards and the standards required by the ARPPIPS, we will not transfer your personal information.
- If the PIA allows us to transfer the personal information to such an organization outside Quebec, we will sign what is generally called a "Data Processing Agreement", or DPA, or conclude other contractual provisions with the organization, which protects the personal information transferred to them and limits their use of it to what we have contracted with them to do. This DPA will adhere to the requirements of the ARPPIPS.
13Complaints / Contact Us
If you believe that we have violated your privacy rights, you may file a complaint with us by notifying us at privacy@skiin.com. You may also file a complaint with (depending on your location) the Office of the Information and Privacy Commissioner of Ontario, the Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information if you feel that your rights have been violated. There will be no retaliation from Myant Medical Corp. for making a complaint.
SKIIN Attn. Privacy
2660 Speakman Drive, Mississauga, Ontario Canada L5K 2L1
Privacy questions and complaints: privacy@skiin.com
Need help understanding our policies?
Our team is here to answer any questions you may have.