Biometric Data Notice
This Biometric Data Notice (“Notice”) explains how Allheartz, Inc. (“Allheartz,” “we,” “us,” or “our”) collects and uses biometric data through the Allheartz Clinical Platform (the “Clinical Services”). It is incorporated by reference into, and should be read together with, the Clinical Terms & Conditions and Privacy Policy, and you consent to the practices described here where required by law, including by accepting those documents. Where Allheartz handles Protected Health Information (“PHI”) on behalf of your healthcare provider, it does so as a Business Associate under a Business Associate Agreement (“BAA”), and that agreement and your provider’s Notice of Privacy Practices also govern how your information is handled.
1. What biometric data we collect
To support your care, the Clinical Services collect and analyze biometric identifiers and biometric information, including video of your body and the movement, gait, posture, and biomechanical patterns derived from it. These are treated as biometric data under laws such as the Illinois Biometric Information Privacy Act (“BIPA”) and similar state laws.
2. Why we collect it
Your biometric data is used to capture and measure movement, track rehabilitation progress and adherence, support remote therapeutic monitoring (“RTM”) workflows, and make results available to your care team — in each case to support, not replace, your provider’s clinical judgment. In de-identified form (see Section 4), it may also be used to improve the platform and develop and refine our analytical models.
3. How we store and protect it
Your biometric data is stored on secure cloud infrastructure and protected by administrative, technical, and physical safeguards. Where our cloud hosting provider creates, receives, maintains, or transmits PHI, it does so under a Business Associate Agreement and the security protocols it makes available. Access is limited to those who need it to provide the Clinical Services.
4. De-identification for platform improvement
Allheartz maintains a separate pool of de-identified data — de-identified in accordance with the HIPAA de-identification standard (45 CFR § 164.514) — that it may use and retain indefinitely to improve the platform and develop its models. Where model development requires review of identifiable video or other PHI (for example, to verify or correct movement keypoints), Allheartz does so only as permitted by the applicable Business Associate Agreement or a valid patient authorization, and otherwise de-identifies the data first. PHI is used or disclosed only as permitted by the applicable BAA and law.
5. How long we keep it, and when we destroy it
Your biometric data is retained and destroyed in accordance with the applicable BAA, your provider’s record-retention obligations, and applicable law. Because this data is handled as part of your care, its retention follows your provider’s and the covered entity’s requirements — which may be longer than for consumer data — rather than a fixed period set by Allheartz.
6. We do not sell your biometric data
Allheartz will not sell, lease, trade, or otherwise profit from your biometric data.
7. Who we may share it with
We may share your biometric data with your authorized healthcare providers and care-team personnel, affiliated healthcare organizations involved in your care, and service providers that help operate the Clinical Services under appropriate confidentiality and security obligations. We may also disclose it as permitted or required by the BAA and law.
8. Your consent is voluntary, and you can withdraw it
Providing this consent is voluntary, though some features of the Clinical Services depend on biometric data and may not function without it, and your care decisions remain with your provider. You may withdraw your consent at any time by contacting your provider or hello@allheartz.com; withdrawal stops future biometric collection and, on request, leads to deletion as described in Section 5, subject to the BAA and legal or record-retention requirements.
9. Consent for minors
For any patient under 18, a parent or legal guardian must provide this consent on the minor’s behalf, consenting to the collection, use, storage, and sharing of the minor’s biometric data as described here.
10. Relationship to our other documents
This Consent supplements the Clinical Terms & Conditions, the Privacy Policy, and any applicable BAA and provider Notice of Privacy Practices. If there is any conflict specifically regarding biometric data that is not PHI governed by the BAA, this Consent controls; PHI remains governed by the BAA and applicable law.
11. Your consent
By accepting the Clinical Terms & Conditions and Privacy Policy, you provide your informed, written consent to Allheartz’s collection, storage, use, and sharing of biometric data as described in this Notice, to the extent such consent is required and not otherwise governed by the BAA or your provider. For a minor, the parent or legal guardian provides this consent on the minor’s behalf.
Consent recorded electronically — the platform stores the accepting person, the document version, and the date and time of consent.
12. Contact
Allheartz, Inc., Oakland, California. Questions about biometric data may be sent to hello@allheartz.com.