Privacy Policy
November 2nd, 2022
Myant Inc. Data Privacy Policy
EFFECTIVE DATE: May 15, 2022
Welcome to SKIIN! This Privacy Policy (“Policy”) describes how SKIIN, uses, and discloses information that we obtain about your use of the skiin.com website (the “Site”) and the SKIIN Mobile software (“the App”), collectively “the Service,” including information that we collect from the SKIIN devices that you connect to a mobile device running the App. This document describes the privacy policy between the purchaser, identified as (“you”) in the current agreement, and Myant Inc. (“Myant”, “SKIIN” “us”, “our”, or “we”) about the SKIIN product.
By using or downloading the Service, you agree that your personal information, including any information about your health that you provide directly to us or that we collect through your use of the Service, may be transferred to, stored, and handled as described in this Policy.
Myant Inc. is committed to complying with the Privacy Rule and maintaining the confidentiality of an individual's PHI through appropriate, authorized access, uses, and disclosures.
As per the Personal Information Protection and Electronic Documents Act (PIPEDA) and Personal Health Information Protection Act (PHIPA), Myant Inc. must reasonably safeguard protected health information (PHI) from any intentional or unintentional use or disclosure. Myant Inc. must create, store, maintain, use, transmit, collect, and disseminate PHI in an environment that promotes confidentiality and integrity without compromising PHI.
PACE Cardiology Patients
If you are a PACE Cardiology patient, please navigate to this link for additional information about PACE Cardiology's Information Practices.
The Information We Collect About You. We collect information directly from you, from devices and third-party services you connect, as well as automatically through your use of our Service.
When You Create, Update, or add information to Your Profile. When you register to use the Service, we collect the personal information you provide us, including your name, email address, password, gender, height, and birthdate. We also collect any additional information you choose to add to your profile, including weight, body mass index (BMI), whether you are a smoker or non-smoker, medical conditions, blood pressure, information related to medications you are taking, patient ID, sleep metrics, stress levels, activity levels, and other personal or health information.
We collect additional information from Devices you connect to your App:
- When you use a SKIIN Device- We collect your raw electrocardiogram (ECG) measurement data, average heart rate, and location on the body where the ECG recording was taken (e.g., body or chest). We collect additional information from your mobile device at the time of recording, including accelerometer data, local time, local time zone, and geographic location.
- You may use your mobile device to add notes, tags, or voice memos to recordings you make with any connected device. Many users use this feature to supplement ECG readings with information about their symptoms, activities, or diet related to their specific health conditions. Voice memos are automatically transcribed and included with the applicable ECG recordings. Please note that we collect information provided through notes, tags, or voice memos, including any personal or sensitive information you choose to provide through this feature.
- You may use your mobile device to add notes, tags, or voice memos to recordings you make with any connected device. Many users use this feature to supplement ECG readings with information about their symptoms, activities, or diet related to their specific health conditions. Voice memos are automatically transcribed and included with the applicable ECG recordings. Please note that we collect information provided through notes, tags, or voice memos, including any personal or sensitive information you choose to provide through this feature.
- Information Collected from Your Phone- In addition to the collection described above, we collect basic information from your mobile device, including device model and OS version, device ID, device language, activities within the App and how long the App is open.
- If you choose to connect your mobile device to a compatible third-party service, such as Apple Health or Google Fit, with your permission, we collect information from your user profile including username and email address, heart rate BPM, step count and distance traveled, activity sample, glucose and oxygen saturation levels, active and resting energy levels, sleep analysis, blood pressure readings, and workout history.
- If you choose to connect your mobile device to a compatible third-party service, such as Apple Health or Google Fit, with your permission, we collect information from your user profile including username and email address, heart rate BPM, step count and distance traveled, activity sample, glucose and oxygen saturation levels, active and resting energy levels, sleep analysis, blood pressure readings, and workout history.
- When You Use A Premium Feature. When you choose to participate in a premium service, we collect additional information from you related to those services. Some premium features are paid services. When you make payments through the Service, you may need to provide your shipping address and financial account information, such as your credit card number, to our third-party service providers. We may receive transaction identifiers and summary information that does not include credit card or bank account numbers.
- When You Contact Us. When you contact SKIIN directly, such as when you contact our Customer Support team, we will receive the contents of your message or any attachments you may send to us, as well as any additional information you choose to provide.
How We Use Your Information
We process your information, including your personal information, for the following purposes:
- To provide our service to you, to communicate with you about your use of our service, to respond to your inquiries, and for other customer service purposes.
- To tailor the content and information that we may send or display to you, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the service.
- To research and develop new products and features.
- For marketing and promotional purposes, to the extent permitted by law and, where required, with your consent. For example, we may use your information, such as your email address, to send you news and newsletters, special offers, and promotions, or to otherwise contact you about products or information we think may interest you. We also may use the information that we learn about you to assist us in advertising our services on third-party websites. You can opt-out of receiving marketing at any time as described below.
- To better understand how users’ access and use our service, both on an aggregated and individualized basis, to improve our service and respond to user desires and preferences, and for other analytical purposes.
- To tailor the content and information that we may send or display to you, to understand if a recorded ECG is your personal data or a guests’ data, to offer location customization, and personalized help and instructions, and to otherwise personalize your experiences while using the service.
- To administer surveys and questionnaires.
- To comply with legal obligations, as part of our general business operations, and for other business administration purposes.
- Where we believe necessary to investigate, prevent or act regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person or violations of our Terms of Use or this Privacy Policy.
How We Share Your Information. We may share your information, including personal information, as follows:
- With Your Consent- With your prior consent, we may share information from the service with other third-party partners, including your personal information and data collected from your devices.
- Your Healthcare Providers or Family- With your consent, we may share your information, including information collected from your connected devices, with your healthcare providers and/or family members (e.g., immediate family or friends) that you designate to receive your information.
- Clinical Trial Studies- By using this service, you consent to Myant sharing information collected by the service with physicians and staff of clinical trial programs who may use the service as a means of collecting data for the trial study. If the service is used as part of a clinical trial study, we will use and share information about the clinical trial collected through the service in accordance with our agreement with the clinical trial program and any privacy notices provided to you as part of the clinical trial program.
- Other Health-Focused Mobile Apps- With your consent we may share your profile information and data collected from your connected devices with other health-focused mobile applications installed on your mobile device to help you track your health and wellness information. If you share your information with these apps, your personal information, including your health information, will be used in accordance with those apps' separate privacy policies, not this one.
- De-Identified Information- We may share de-identified information—so that it cannot reasonably be used to identify an individual—with third parties for marketing, advertising, research, or similar purposes.
- Health Researchers- With your consent Myant Inc. may share data collected through the service with healthcare researchers and other research organizations, including de-identified profile information and data collected from your connected devices. For example, we may share information such as your gender, height, weight, information about medications you have provided, and data from your connected devices, but we will not share your name or other information that could identify you.
- Affiliates- With your consent we may disclose the information we collect from you to our affiliates or subsidiaries; however, if we do so, their use and disclosure of your personal information will be subject to this Policy.
- Service Providers- With your consent we may disclose the information we collect from you to third party vendors, service providers, contractors or agents who perform functions on our behalf, such as providers of hosting, email communication, customer support services, analytics, marketing, and advertising, based on our instructions, and in compliance with this policy and any other appropriate confidentiality and security measures.
- Business Transfers- If we are acquired by or merged with another company, if substantially all our assets are transferred to another company, or as part of a bankruptcy proceeding or reorganization, we will give affected users notice before transferring any personal information to a new entity.
- In Response to Legal Process- We may disclose the information we collect from you to comply with the law, a judicial proceeding, court order, or other legal process, such as in response to a court order or a subpoena.
- Please note: Our policy is to notify you of legal process seeking access to your information, such as search warrants, court orders, or subpoenas, unless we are prohibited by law from doing so. In cases where a court order specifies a non-disclosure period, we provide delayed notice after the expiration of the non-disclosure period. Exceptions to our notice policy include exigent or counterproductive circumstances, for example, when there is an emergency involving a danger of death or serious physical injury to a person.
- To Protect Us and Others- We may disclose the information we collect from you where we believe it is necessary to investigate, prevent, or act regarding illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms of Use or this Policy, or as evidence in litigation in which SKIIN is involved.
- Third Party Analytics- We use automated devices and applications, such as Google Analytics and Mixpanel, to evaluate usage of our service. We may use other analytic means to evaluate our service. We use these tools to help us improve our service, performance, and user experiences.
Consent
Myant Inc. will obtain consent before any collection, use or disclosure of any personal identifiable information (PII) and personal health information (PHI) for purposes that we have identified. Individuals who sign up for a SKIIN account will provide explicit consent during account creation.
By using the Service or providing us with any PII and PHI, you consent to the transfer to, and processing, sharing and storage of your information as set forth in this Privacy Policy. Please note that other countries may have privacy and data protection regulations that are not on par with the regulations in Canada and may not provide the same level of protection.
We will always ask for your consent if we ever share or use your PII and/or PHI for a purpose other than what is in this Privacy Policy. At any point, you can withdraw your consent by contacting us at [email protected].
Security of My Personal Information
Your privacy is important to Myant Inc., and we enforce privacy measures to ensure that your PII and PHI is protected against unauthorized access, use and modification.
All data is protected through an AES256-bit encrypted database and data during any transfer between the database, server and mobile application is encrypted using HTTPS.
Our data exists in a private virtual cloud, hosted by Amazon Web Services (AWS). AWS provides features that help in maintaining secure data through security groups, network access control lists and flow logs. AWS has ISO 27001, ISO 27017, and ISO 27018 certifications, ensuring it meets international standards for information security management systems, security controls for cloud services and security techniques for protection of personally identifiable information.
During SKIIN account creation, a complex password (between 8 to 30 characters and a minimum of one special character or number) is required for all users. The authentication process requires email confirmation before a user can log into the application. Resetting forgotten passwords will also require email confirmation.
Only authorized individuals can access users’ PII and PHI data on secure databases, which can only be accessed through secure passwords. Employees are required to sign documentation that obliges them to protect users’ PII and PHI and will only be able to access PII and PHI to fulfill their job requirements.
We also encourage you to take your own security measures, such as the following:
- Not sharing your password with anyone else
- Remembering to log out of the Service if accessing it on someone else’s personal device
- Updating your password regularly
- Having a password on your personal device
- Locking your personal device when not in use
Security Breaches
As per the Personal Information Protection and Electronic Documents Act (PIPEDA) and Personal Health Information Protection Act (PHIPA), when impermissible or unauthorized access, acquisition, use, and/or disclosure of an individual’s Protected Health Information (PHI) handled by Myant Inc. occurs, we are required to keep records and notify any involved individuals of all breaches and to report to the Privacy Commissioner of Canada of any security breaches that pose a significant risk of harm to any individual or the public.
Your Rights Regarding Your Health Information
You have certain rights regarding your health information, which are explained below. You may exercise these rights by submitting a request in writing to [email protected]
- Right to inspect and copy: If you would like to inspect or receive a copy of your PHI that is contained in a designated record set (e.g., health and billing records), we are required to provide you access to such information within 30 days after receipt of your request (with up to a 30-day extension if required with notice). We may charge you a reasonable fee to cover duplication, mailing and other costs incurred by us in complying with your request. We may deny your request for access to your personal information as permitted by PIPEDA/PHIPA. For example, we may deny your request if we believe the disclosure will endanger your life or that of another person. Depending on the circumstances of the denial, you may have a right to have this decision reviewed.
- Right to Request Restrictions on Use and Disclosure: You have the right to request a restriction or limitation on certain uses and disclosures of your health information. To request restrictions, you must make your request in writing to [email protected]. In your request, you must tell us:
- What information you wish to limit
- Whether you wish to limit our use, disclosure, or both
- To whom you want the limits to apply – for example, if you want to prohibit disclosures for insurance payment, health care operations, for disaster relief purposes, to persons involved in your care, or to your spouse.
- Right to Request Amendment: If you believe that any health information, we have about you is incorrect or incomplete, you have the right to ask us to change the information for as long as Myant Inc. maintains the information. To request an amendment to your health information, your request must be in writing, signed, and submitted to Myant Inc. If we deny your request, we will provide you with a written explanation. You may respond with a statement of disagreement that will be maintained with your records. We will respond to your request within 60 days (with up to a 30-day extension if needed with notice).
- Right to Receive Confidential Communications: You have the right to request that we communicate with you about your health information in a confidential manner or at a specific location. For example, you may ask that we only contact you via mail to a post office box. You must submit your request in writing to Myant Inc. We will not ask you the reason for your request. Your request must specify how or where you wish to be contacted. We will accommodate all reasonable requests.
- Right to Receive an Accounting of Certain Disclosures: With some exceptions, you have the right to receive an accounting of certain disclosures we have made, if any, of your health information. Your accounting request must be in writing and signed by you or your personal representative and submitted to Myant Inc. Your request must specify the time in which the disclosures were made. You may receive one free accounting in any 12-month period. We will charge you for additional requests. This right only applies to disclosures for purposes other than treatment, payment or health care operations as described in this Notice. It also excludes disclosures we may have made to you, your family members or friends involved in your care. The right to receive this information is subject to certain exceptions, restrictions and limitations as allowed by PIPEDA/PHIPA.
- Right to Obtain a Copy of this Notice: You have the right to receive a paper copy of this Notice upon request, even if you have agreed to receive the Notice electronically. You may ask us to give you a copy of this Notice at any time.
- Right to Cancel Authorization to Use or Disclose: Other uses and disclosures of your health information not covered by this Notice or the laws that govern us will be made only with your written authorization. You have the right to revoke your authorization in writing at any time, and we will discontinue future uses and disclosures of your health information for the reasons covered by your authorization. We are unable to take back any disclosures that were already made with your authorization, and we are required to retain the records of the care that we provided to you.
What Choices Do I Have Regarding Promotional Emails?
We may send periodic promotional emails to you. You may opt-out of such communications by following the opt-out instructions contained in the email. Please note that it may take up to 30 business days for us to process opt-out requests. We may still send you emails about your account or any services you have requested or received from us.
Users Under 18
Our services are not designed for users under 18. If we discover that a user under 18 has provided us with personal information, we will delete such information from our systems.
COMPLAINTS/CONTACT US
If you believe that we have violated your privacy rights, you may file a complaint with us by notifying us at [email protected]. You may also file a complaint with the Office of the Information and Privacy Commissioner of Ontario if you feel that your rights have been violated. There will be no retaliation from Myant Inc. for making a complaint.
SKIIN Attn. Privacy
100 Ronson Drive
Etobicoke, Toronto, ON
M9W 1B6
[email protected]