Privacy Policy for Binah Check and Binah Connect apps

This privacy policy (“Privacy Policy”) governs the data collection, processing, and usage made by Binah.ai Ltd. (“Company”, “we” or “us”). This Privacy Policy concerns the data we collect from individuals who have installed and are interacting with our mobile apps including Binah Check and Binah Connect or using the My Binah Check management dashboard (respectively “App”, “users”, “Dashboard” and collectively the “Services”). Each of the users shall also be referred to herein as “you”. This Privacy Policy is also an integral part of the applicable terms of use, or any other agreement entered into between you (or the entity that you are acting on its behalf) and us.

By using the Services, you agree to the collection and use of your data in accordance with this Privacy Policy. When using the Services, we may collect and process certain Personal Data from you to allow you to use the Services, as well as for other purposes as detailed below. By using the App, Dashboard and Services, you consent to the privacy practices described in this Policy.

If you have any questions about this Privacy Policy, please contact us at: support@binah.ai.

AMENDMENTS

We reserve the right to periodically amend or revise the Privacy Policy, which will immediately affect the implementation of the revised Privacy Policy on the App or Dashboard. The last revision date will be reflected in the “Last Modified” heading located at the top of the Privacy Policy. We will make a reasonable effort to notify you if we implement any changes that substantially change our privacy practices. We recommend that you review this Privacy Policy periodically to ensure that you understand our privacy practices and to check for any amendments.

  1. Who are we and Contacting Us

Binah.ai Ltd., registration number 515413482

2 Zeev Jabutinsky St.,

Ramat Gan, 5250501

Israel

Email: support@binah.ai

Where you are a direct user of the Services, a browser or visitor of our Services, or contacting us directly, we process your personally identifiable information as the controller, meaning that legally, we deem as the owner of your personally identifiable information. In those cases, and for GDPR purposes, we assume the role of Data Controller, and any of our external suppliers shall be deemed as Data Processor.

In some other cases, the App may be provided to you by us as part of our engagement with certain third party, such as your employer (“Account Owner”). In those cases, the Account Owner may be the sole Controller or joint Controller of your data, while we act as a Data Processor processing the data on their behalf. In those cases, some aspects of the Processing of your data may be subject to separate agreements and privacy policies provided by your Account Owner.

Questions, comments, requests and complaints regarding this Privacy Policy and the information we hold are welcome and should be addressed to us by using the contact details above. All requests will be dealt with promptly and efficiently. In addition, you can always address your questions and concerns to anyone on the Study team.

Our Data protection Representation under the GDPR

We value your privacy and your rights as a European data subject and have therefore appointed Prighter as our privacy representative and your point of contact. Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter or make use of your data subject rights, please visit: https://prighter.com/q/17807568507

  1. The Data we process

Processing of Non-Personal Data

As part of providing you with the Services, we may collect aggregated, non-personal and non-identifiable information which may be made available or gathered via your use of the Services and your interaction with us (“Non-Personal Data“). Further, we may process identified Personal Data to create a new data set which is not identified under common standards and applicable laws. Such a new data set will be considered as Non-Personal Data. Non-Personal Data may be used by us without limitation and for any purpose, including for commercial, research, or statistical purposes, without further notice to you. If we combine Personal Data with Non-Personal Data, we will treat the combined data as Personal Data.

Processing of Personal Data

As part of using the App or Dashboard, you will be required to register and open a user account (whether directly or through the use of access info provided to you), while providing your basic contact info, credentials and other basic data including your demographics such as sex, age, etc. Further, during the use of the Services, some usage data may be processed and kept by us, such as your measurements and vitals, stress levels, and general usage data as the dates and times of use. Such data may be deemed as “Personal Data”, namely information that identifies an individual or may with reasonable effort be used to identify an individual (“Personal Data” or “Personal Information” as defined under applicable law).

Please see below the table which specifies the Personal Data we collect and how we use it.

DATA SET
PURPOSE AND PROCESSING OPERATIONS
LAWFUL BASIS UNDER THE GDPR
Data Collected from App Users
Basic Account Data
The User Account data includes basic contact details such as name, email address, , hashed login password , and your device details (type, OS version, etc.). Further, we may also collect relevant demographic data such as age, sex, height, weight, etc.
We collect such data to allow you to access and use the App, while adapting the App’s calculations and algorithms to your characteristics. 
Further, we may use the demographic data and device technical information to evaluate our services (sometimes for the benefit of the relevant Account Owner), improve and develop our services, including through research and development of new products and algorithms. 
We will collect and process the Account Data, create a User Account in our systems, identify the User when accessing and registering to the Services and adjust the Services to the User’s preferences and characteristics. Also, we may use your contact details to send you updates and notifications regarding your use of the Services. 
For evaluation. Improvement and research purposes, we may analyze your use, aggregate the data and create de-identified sets of data for our use.
The lawful basis for processing your Account Data will be the contract between you and us, meaning we will use the data to provide you with Services. 
Usage for general improvement and further development of our services is part of our legitimate interest.
*** Any processing of health-related data for our own purposes is always subject to the consent obtained from you during the registration. You can always withdraw your consent as detailed below.
 
*** As explained above where we process your data as part of an agreement with an Account Owner, your data may be shared with and transferred to that Account Owner as the Controller of such data. Any further processing of the transferred data by the Controller is not under our control or responsibility.  
Vital Signs and Health-Related Data
As part of using the App, including through any connected devices such as fitness strap, certain health-related data may be collected and processed regarding the user, such as Blood Pressure, Heart Rate (BPM), Respiration (RPM), Stress level and HRV-SDNN (ms), and other calculated biomarkers and related data, including a calculated “Binah Wellness Score”, to track and maintain your historical measurement data.
We use that data to provide you with the Services, which encompasses collection, tracking and management of certain body and biomarkers, stress levels, wellness, etc. 
Further, we may use biomarkers and health-related data to evaluate our services (sometimes for the benefit of the relevant Account Owner), improve and develop our services, including through research and development of new products and algorithms. 
To extract vital-sign measurements, the App uses only a video of a small patch of skin from the user’s face or finger, without any identifiable feature such as eyes. That video footage is processed locally (on the user’s device) in real-time, is not retained once the measurement ends and is not transferred to our servers. Only the extracted measurements are being shared with our cloud, and processed as part of the user’s account. 
Processing of health-related data, whether for the provision of the Services or for the further development of our services, is always subject to your consent provided through the App’s interfaces. 
*** Sometimes such Vital Signs and Health-related Data will be sent directly to the relevant Account Owner cloud and IT infrastructure. In those cases we do not have any access to such data and the Account Owner is solely responsible to its processing and usage under its independent privacy policies and practices.  
 
Apple Health and Fitness Kit Data
We will collect and process health and fitness data collected through your apple mobile device as part of Apple Health and Fitness Kit (“HealthKit data”). We will collect and access such data through the apple applicable authorized API. The use of Apple’s Health Kit is bilateral meaning we may share certain information with Apple. App’s Information that can be shared and stored with HealthKit:
– Pulse Rate
– Respiration Rate
– Heart Rate Variability (HRV) SDNN
We will use this HealthKit data in order to provide you with our Services and to develop statistical analysis of the relative effectiveness of our Services.
Sharing of Application’s data with Apples HealthKit is always subject to your prior consent. You can withdraw your consent to the application sharing with HealthKit at any time within the relevant Apple Inc. application (e.g. Apple Health). Withdrawing your consent will not prevent you from using the application.
Usage Data
When you use the App, information and data gets automatically generated and collected that can help us to understand how you are using the App, and how to better provide the Services to you (“Usage Data”).
Most Usage Data is not personal – e.g., click stream within the App, page viewed, the use of the Services (i.e., accessed or used by end user) and the time spent on those pages or features, crash data and analytics, etc.
To the extent Usage Data contains Personal Data, it will be treated as personal data and is covered under this Privacy Policy.
We use Usage Data to improve our Services.
 
We may use specific third-party tools for the collection, analysis and management of Usage Data, namely SDKs implemented in the App.
We process such information subject to our legitimate interest.
Contact Us and Support
If you voluntarily contact us in order to ask for information regarding our Services or any other inquiry, you may be required to provide us with certain information such as your name, email address, phone number, the company which on its behalf you are contacting us, the industry you are related to, and additional information you decide to share with us.
 If you are contacting us on behalf of another person, we value your assistance and care for others, please note that it is your responsibility to make sure that any person whose Personal Data you provide is aware of the principles of this statement and agrees that you will provide Personal Data to us on this basis.
We will use this data to provide you with the information you requested, respond to your inquiry, or provide our Services. We may process the content of our correspondence with you to improve customer service, and in the event, we believe it is required in order to provide you with any further assistance (if applicable).
The correspondence and its contents with you may be processed and stored by us in order to improve our customer service and in the event, we believe it is required to continue to store it, for example, in the event of any claims or in order to provide you with any further assistance (if applicable).
We process such data and retain any inquiry history subject to our legitimate interests.
Data We Collect from Dashboard Users
Account Data
The User Account data includes basic contact details such as name, email address, hashed login password, technical information regarding your device, etc.
We collect such data to allow you to access and use the Dashboard, while adapting the Dashboard’s calculations and algorithms to your characteristics.
We will collect and process the Account Data, create a User Account in our systems, identify the User when accessing and registering to the Services and adjust the Services to the User’s preferences and characteristics. Also, we may use your contact details to send you updates and notifications regarding your use of the Services.
The lawful basis for processing your Account Data will be the contract between you and us, meaning we will use the data to provide you with access to the Dashboard.
 
*** If your use of the Dashboard is under an Account Owner, sometimes the collection and use of your data is done as part of our agreement with such Account Owner who is solely responsible for the lawfulness of processing of your data.
 
Technical Data
typically collected and generated automatically, directly from the User’s device and through their interaction with the Services, including online identifiers associated with your device (such as IP address), dates and times of use, language, resolution, light and other view preferences, battery consumption, analytical data regarding the usage of the services, etc. Also, we may collect some technical and online identifiers data by cookies, pixels, web beacons and other similar technologies (“Cookies”).
 
***Please see additional information regarding Cookie’s usage below.
We use that data for improving & customizing the Dashboard, safety, security and fraud prevention of the dashboard, and sometimes for marketing purposes.
We, directly or through the use of third parties, will collect your data, aggregate it and statistically analyze it (whether alone or together with other Visitor’s data), aggregate, generate reports based on such analysis and retain records of any such usage data. We process and retain this data for enhancing your experience and auditing and tracking usage statistics and traffic flow, customizing the Services for you, or adjusting its content, including advertisements, for your use. We also process it to protect the Service’s security and our and third parties’ rights (subject to applicable law requirements).
We use the usage data based on the contract necessity to provide you with the information requested. Further, we may use Usage Data internally to improve our services, , and create new features and services subject to our legitimate interests. Any use of Cookies or other technologies for marketing or other purposes that are not an inherent part of the Services operation will be done only following your consent provided through the designated tool or banner in the Dashboard.
Contact Us and Support
If you voluntarily contact us in order to ask for information regarding our Services or any other inquiry, you may be required to provide us with certain information such as your name, email address, phone number, the company which on its behalf you are contacting us, the industry you are related to, and additional information you decide to share with us.
If you are contacting us on behalf of another person, we value your assistance and care for others, please note that it is your responsibility to make sure that any person whose Personal Data you provide is aware of the principles of this statement and agrees that you will provide Personal Data to us on this basis.
We will use this data to provide you with the information you requested, respond to your inquiry, or provide our Services. We may process the content of our correspondence with you to improve customer service, and in the event, we believe it is required in order to provide you with any further assistance (if applicable).
The correspondence and its contents with you may be processed and stored by us in order to improve our customer service and in the event, we believe it is required to continue to store it, for example, in the event of any claims or in order to provide you with any further assistance (if applicable).
We process such data and retain any inquiry history subject to our legitimate interests.

Please note that the actual processing operation per purpose of use and lawful basis detailed in the table above, may differ. Such processing operation usually includes a set of operations, made by automated means, such as collection, storage, use, disclosure by transmission, erasure or destruction. Transfer of Personal Data to third party countries as further detailed in the Data Transfer section is based on the same lawful basis as stipulated in the table above.

In addition, we may use certain Personal Data to prevent potentially prohibited or illegal activities, fraud, misappropriation, infringements, identity thefts and any other misuse of the Services and to enforce the Terms, as well as to protect the security or integrity of our databases and the Services, and to take precautions against legal liability. Such processing is based on our legitimate interests.

  1. HOW WE COLLECT INFORMATION
  1. COOKIES & TRACKING TECHNOLOGIES

When you use the Dashboard, we or our third-party service providers may use Cookies to gather, store, and track certain information related to your access of, activity and interaction with the Dashboard.  You can find out more information about cookies at www.allaboutcookies.org.

The usage of Cookies in the Dashboard is under your control per the Cookie bar installed in our dashboard. You may also remove Cookies by following the instructions on your device governing the setting of your preferences. Our Cookies do not enable any access to or inspection of other information on your device. If you wish to be notified of when Cookies are placed on your device, you may set your web browser to provide such notices.

Most browsers will allow you to erase cookies from your computer’s hard drive, block acceptance of cookies, or receive a warning before a cookie is stored. However, if you block or erase cookies your online experience may be limited. Please see the following links for more information with respect to how you can block or erase cookies via your particular browser: Google Chrome; Firefox; Internet Explorer; Safari; Edge; Opera.

In the App, we may use specific tracking and analysis technologies, mainly known as SDKs for collection and analysis of usage data for monitoring and improvement purposes as explained above.

  1. DATA SHARING

We share your data with third parties, including with trusted partners or service providers that help us provide our services and improve our services:

CATEGORY OF RECIPIENT
DATA THAT WILL BE SHARED
PURPOSE OF SHARING
Account Owners
Who engaged us to provide you with the Services (e.g., employer)
Personal Date such as Account Information, biomarkers statistics, Contact Information, etc.
We use the usage data based on the contract necessity to provide you with our services.
In some cases, Vital Signs and Health-related Data are being transmitted directly from your device through our App to the relevant Account Owner, while we do not retain nor process such data.
Any further use of such transferred data is subject to our agreements with the Account Owner as the Controller of relevant data, as well as the Account Owner independent privacy policies and practices, as the Controller of such data.
Service Providers
All types of Personal Data
We employ other companies and individuals to perform functions on our behalf. Examples include: sending communications, processing payments, analyzing data, providing marketing and sales assistance (including advertising and event management), identifying errors and crashes, conducting customer relationship management, and providing training. These third-party service providers have access to Personal Data needed to perform their functions, but they are prohibited from using your Personal Data for any purposes other than providing us with requested services.
Any acquirer of our business
All types of Personal Data.
We may share Personal Data, in the event of a corporate transaction (e.g., sale of a substantial part of our business, merger, consolidation or asset sale). In the event of the above, our affiliated companies or acquiring company will assume the rights and obligations as described in this Policy.
Legal and law enforcement 
Subject to law enforcement authority request.
We may disclose certain data to law enforcement, governmental agencies, or authorized third parties, in response to a verified request relating to terror acts, criminal investigations or alleged illegal activity or any other activity that may expose us, you, or any other user to legal liability, and solely to the extent necessary to comply with such purpose.

Where we share information with service providers and partners, we ensure they only have access to such information that is strictly necessary in order for us to provide the services. These parties are required to secure the data they receive and to use the data for pre-agreed purposes only, while ensuring compliance with all applicable data protection regulations.

We use the following SDK (a Software development kit) which is a set of tools that provide us with the ability to build a custom app which can be based on, or connected to, another program. SDKs are used only in our App. SDK create the opportunity to enhance our App with more functionality, as well as include advertisement and push notifications, if applicable.

The specific SDK we currently use, purpose of use, their privacy policy and opt-out controls are set forth in the table below:

SDK
Purpose 
Privacy Policy Link
MixPanel
Monitoring the App’s usage via Segment
Segment
Used as a data broker for Mixpanel
Sentry
Error tracking system
  1. HealthKit shared information

This section of our privacy policy describes how the Application interacts and shares data with Apple HealthKit.

With your consent, the application enables sharing specific application measured results with Apply HealthKit. In such case, the application shares the information collected through the usage of the Application with Apple HealthKit, so the such data will be processed as stored as part if the User’s HealthKit data, for the user usage only. The Application does not retrieve the HealthKit information and We do not get any access to the HealthKit Data.   Application’s Information that can be shared and stored with HealthKit includes:

Sharing of Application’s data with Apples HealthKit is always subject to your prior consent. You can withdraw your consent to the application sharing with HealthKit at any time within the relevant Apple Inc. application (e.g. Apple Health). Withdrawing your consent will not prevent you from using the application,

Your HealthKit data is not being used for advertising, and We do not sell or share your HealthKit Information to third party advertising platforms, data brokers or information resellers. Nor will we use your HealthKit Information for data-mining activities; and we will not disclose HealthKit Information to any third-party. 

  1. Your Data Subjects’ rights under Privacy Protection laws

Under relevant privacy laws, individuals may possess specific rights that allow them to request information or modifications in how we process their personal data. These rights may include the following:

To exercise any of these rights, please contact us through the provided means of communication, directly to us or through our Data Protection Representative. We may not always be able to fulfill your request, and not all of these rights are applicable in every jurisdiction or in every case. Where we are not able to provide you with the information which you have requested, we will endeavor to explain the reasoning for this and inform you of your rights, including the right to complain to the relevant supervisory authority. We reserve the right to ask for reasonable evidence to verify your identity before providing you with any such information per applicable law.

If you are a user of the Services under an Account Owner, some or all of your rights, may be only exercised under the responsibility and discretion of such Account Owner. In such cases, please contact your Account Owner directly. Any inquiry transferred to us regarding such data will be forwarded by us to the relevant Account Owner as the Controller of such data.

If you are not satisfied, you have the right to file a complaint with the appropriate data protection supervisory authority at any time. However, we would appreciate the opportunity to address your concerns before you involve the authorities. Please do not hesitate to contact us initially.

  1. Data retention

In general, we retain the Personal Data we collect for as long as it remains necessary for the purposes set forth above, all under the applicable regulations, or until you express your preference to opt out, where applicable.

The criteria used by us to determine our retention periods are as follows:

At our sole discretion, we may rectify or erase information from our systems without prior notice to you, once we deem it no longer necessary for such purposes.

  1. SECURITY

We use physical, technical, and administrative security measures for the Services that we believe comply with applicable laws and industry standards to prevent your information from being accessed without the proper authorization, improperly used or disclosed, unlawfully destructed or accidentally lost.

However, unfortunately, the transmission of information via the internet and online data processing cannot be 100% secure. As such, although we will do our best to protect your Personal Data, we cannot guarantee the security of data transmitted via App or Services and any transmission of your data shall be done at your own risk.

  1. Data Processing Location

We may store or process your Personal Data in a variety of countries, including Israel as we are headquartered there. In any such case we remain responsible for protecting your privacy and data security, in accordance with applicable law requirements.

Suppose you are a resident of a jurisdiction where the transferring of your Personal Data requires your consent. In that case, your consent to this Privacy Policy includes your express consent for such transfer of your data.

We are not responsible for the further processing, including storage and processing location, of any data transferred by us or transmitted from the App to an Account Owner, such data is managed under the sole responsibility and discretion of such an Account Owner as the Controller of such data.

 CHILDREN

Our App and Services are not directed, nor is it intended for use by children (the phrase “child” shall mean an individual that is underage defined by applicable law) and we do not knowingly process a child’s information. Please contact us if you have reason to believe that a child has shared any information with us.

Last Update: July-25-2023