Pr
i
vacy
Pol
i
cy
F
i
nal
LenexaCARE
Pr
i
vacy
Pol
i
cy
Effect
i
ve
date
:
2026-05-19
Vers
i
on
:
1
.
0
Th
i
s
Pr
i
vacy
Pol
i
cy
expla
i
ns
how
Lenexa
Med
i
cal
Pty
Ltd
("Lenexa
Med
i
cal"
,
"we"
,
"us"
,
"our")
collects
,
uses
,
stores
and
d
i
scloses
i
nformat
i
on
when
you
use
the
LenexaCARE
mob
i
le
appl
i
cat
i
on
("the
App")
.
The
App
i
s
a
not
i
f
i
cat
i
on
tool
used
by
care
staff
to
rece
i
ve
alerts
from
LenexaCARE
dev
i
ces
("DataBoxes")
for
detect
i
ng
i
n-bed
,
edge
of
bed
,
and
out-of-bed
pos
i
t
i
ons
.
Please
read
th
i
s
pol
i
cy
carefully
.
By
i
nstall
i
ng
or
us
i
ng
the
App
you
agree
to
the
pract
i
ces
descr
i
bed
below
.
If
you
do
not
agree
,
please
do
not
use
the
App
.
1
.
Who
we
are
Controller
of
personal
data
:
Lenexa
Med
i
cal
Pty
Ltd
ACN
:
624
735
977
Reg
i
stered
off
i
ce
:
Level
1/70
Adam
St
,
Burnley
VIC
3121
,
Austral
i
a
Pr
i
vacy
contact
:
You
may
d
i
rect
any
pr
i
vacy
enqu
i
ry
,
access
request
,
correct
i
on
request
,
or
compla
i
nt
to
the
ema
i
l
address
above
.
We
respond
w
i
th
i
n
30
days
.
2
.
Who
uses
the
App
The
App
i
s
prov
i
ded
to
author
i
sed
staff
(nurses
,
carers
,
superv
i
sors)
of
the
fac
i
l
i
t
i
es
that
l
i
cense
LenexaCARE
from
Lenexa
Med
i
cal
.
The
App
i
s
not
i
ntended
for
use
by
pat
i
ents
or
members
of
the
publ
i
c
,
and
i
s
not
des
i
gned
for
or
d
i
rected
at
ch
i
ldren
under
16
.
Pat
i
ents
do
not
download
or
i
nteract
w
i
th
the
App
.
Informat
i
on
generated
by
sensors
i
n
a
pat
i
ent's
room
i
s
processed
by
the
App
on
behalf
of
the
fac
i
l
i
ty
for
pos
i
t
i
onal
alert
i
ng
purposes
only
.
software@lenexamed
i
cal
.
com
3
.
Informat
i
on
we
collect
We
collect
only
the
i
nformat
i
on
needed
to
operate
the
alert
i
ng
serv
i
ce
,
run
the
aud
i
t
tra
i
l
,
and
meet
our
regulatory
obl
i
gat
i
ons
.
3
.
1
Informat
i
on
about
you
(the
App
user)
When
you
s
i
gn
i
n
or
use
the
App
we
collect
:
Your
work
ema
i
l
address
.
Your
d
i
splay
name
(
i
f
prov
i
ded
i
n
your
account)
.
A
Cogn
i
to-
i
ssued
user
i
dent
i
f
i
er
("user
_i
d")
.
A
dev
i
ce
i
dent
i
f
i
er
("dev
i
ce
_i
d")
that
we
generate
on
the
dev
i
ce
.
Your
dev
i
ce
operat
i
ng
system
and
vers
i
on
(e
.
g
.
"Andro
i
d
14"
,
"
i
OS
17
.
4
.
1")
.
The
vers
i
on
of
the
App
i
nstalled
.
Your
dev
i
ce
t
i
me-zone
(IANA
name
and
UTC
offset)
.
A
F
i
rebase
Cloud
Messag
i
ng
("FCM")
token
that
allows
us
to
del
i
ver
push
not
i
f
i
cat
i
ons
to
your
dev
i
ce
.
Records
of
your
s
i
gn-
i
n
,
s
i
gn-out
,
alert
acknowledgement
,
v
i
deo-v
i
ew
i
ng
and
v
i
deo-sav
i
ng
act
i
ons
i
n
the
App
,
together
w
i
th
the
t
i
mestamp
and
the
dev
i
ce
on
wh
i
ch
the
act
i
on
was
taken
.
3
.
2
Operat
i
onal
and
alert
data
The
App
rece
i
ves
and
processes
the
follow
i
ng
data
from
fac
i
l
i
ty-deployed
DataBoxes
,
on
behalf
of
the
fac
i
l
i
ty
:
DataBox
i
dent
i
f
i
er
("hub
_i
d")
,
wh
i
ch
corresponds
to
a
spec
i
f
i
c
bed
.
Pose-change
events
(e
.
g
.
"
i
n-bed"
,
"edge-of-bed"
,
"out-of-bed"
,
"no
person
present")
detected
by
the
on-dev
i
ce
sensor
.
The
conf
i
dence
and
probab
i
l
i
ty
d
i
str
i
but
i
on
of
each
pose
detect
i
on
.
The
UTC
t
i
mestamp
of
each
detect
i
on
.
An
i
dent
i
f
i
er
and
storage
locat
i
on
for
the
short
sensor-data
cl
i
p
captured
around
each
event
.
Th
i
s
data
i
s
de-
i
dent
i
f
i
ed
.
The
App
does
not
collect
,
store
,
or
d
i
splay
any
pat
i
ent
name
,
date
of
b
i
rth
,
med
i
cal
record
number
,
or
other
pat
i
ent-
i
dent
i
fy
i
ng
i
nformat
i
on
.
The
"hub
_i
d"
i
dent
i
f
i
es
a
bed
,
not
a
person
.
We
treat
th
i
s
data
w
i
th
the
same
safeguards
as
sens
i
t
i
ve
i
nformat
i
on
even
though
i
t
does
not
,
on
i
ts
own
, i
dent
i
fy
any
i
nd
i
v
i
dual
pat
i
ent
.
3
.
3
Informat
i
on
we
do
NOT
collect
We
do
not
collect
,
and
the
App
does
not
request
perm
i
ss
i
on
to
access
,
any
of
the
follow
i
ng
:
Camera
,
m
i
crophone
,
photo
l
i
brary
reads
(we
only
wr
i
te
to
the
photo
l
i
brary
when
you
tap
"Save
to
gallery")
.
GPS
or
prec
i
se
locat
i
on
.
Contacts
,
calendar
,
SMS
,
call
h
i
story
,
or
messag
i
ng
.
Brows
i
ng
h
i
story
or
cl
i
pboard
contents
.
B
i
ometr
i
c
data
.
Pat
i
ent
names
,
med
i
cal
records
,
or
any
other
d
i
rectly
i
dent
i
fy
i
ng
pat
i
ent
i
nformat
i
on
.
We
also
do
not
use
th
i
rd-party
analyt
i
cs
,
advert
i
s
i
ng
,
behav
i
oural-track
i
ng
,
or
crash-report
i
ng
tools
(no
F
i
rebase
Analyt
i
cs
,
no
Google
Analyt
i
cs
,
no
Sentry
or
Crashlyt
i
cs
,
no
M
i
xpanel
,
no
advert
i
s
i
ng
SDKs)
.
4
.
How
we
use
the
i
nformat
i
on
We
use
the
i
nformat
i
on
descr
i
bed
above
for
the
follow
i
ng
purposes
:
Authent
i
cat
i
on
.
S
i
gn
you
i
nto
the
App
and
keep
you
s
i
gned
i
n
for
the
durat
i
on
of
your
sh
i
ft
.
Alert
del
i
very
.
Route
pose-change
events
from
a
DataBox
to
the
staff
ass
i
gned
to
that
bed
,
both
i
n
real
t
i
me
i
ns
i
de
the
App
and
as
system
push
not
i
f
i
cat
i
ons
.
Aud
i
t
tra
i
l
.
Record
who
saw
an
alert
,
when
i
t
was
acknowledged
,
who
acknowledged
i
t
,
and
how
(acknowledged
/
false
alarm)
.
Th
i
s
i
s
requ
i
red
for
accountab
i
l
i
ty
and
operat
i
onal
record-
keep
i
ng
.
Operat
i
onal
support
.
D
i
agnose
techn
i
cal
i
ssues
,
mon
i
tor
serv
i
ce
health
,
and
i
mprove
the
App
.
Compl
i
ance
.
Demonstrate
to
the
fac
i
l
i
ty
,
to
regulators
,
and
to
aud
i
tors
that
the
alert
i
ng
serv
i
ce
operated
correctly
and
that
access
to
alert
data
was
appropr
i
ate
.
We
do
not
use
your
i
nformat
i
on
for
market
i
ng
,
prof
i
l
i
ng
,
automated
dec
i
s
i
on-mak
i
ng
w
i
th
legal
effect
,
or
advert
i
s
i
ng
.
5
.
Who
we
share
i
nformat
i
on
w
i
th
We
do
not
sell
your
personal
i
nformat
i
on
.
We
do
not
share
your
personal
i
nformat
i
on
w
i
th
th
i
rd
part
i
es
for
market
i
ng
or
advert
i
s
i
ng
.
We
share
i
nformat
i
on
only
w
i
th
the
follow
i
ng
categor
i
es
of
rec
i
p
i
ents
,
under
contracts
that
requ
i
re
them
to
handle
i
t
i
n
accordance
w
i
th
appl
i
cable
law
.
5
.
1
Cloud
serv
i
ce
prov
i
ders
(data
processors)
Amazon
Web
Serv
i
ces
,
Inc
.
("AWS")
.
All
App
data
at
rest
(account
i
nformat
i
on
,
alert
h
i
story
,
aud
i
t
logs
,
sensor-data
cl
i
ps
,
snooze
rules)
i
s
stored
i
n
AWS
.
AWS
does
not
access
your
data
except
as
needed
to
prov
i
de
the
serv
i
ces
we
contract
them
for
.
Google
LLC
/
F
i
rebase
Cloud
Messag
i
ng
.
Push
not
i
f
i
cat
i
ons
are
del
i
vered
through
F
i
rebase
Cloud
Messag
i
ng
.
When
the
App
rece
i
ves
an
alert
that
warrants
a
push
not
i
f
i
cat
i
on
,
our
server
sends
a
short
message
(the
bed
i
dent
i
f
i
er
and
a
br
i
ef
pose
descr
i
pt
i
on)
and
your
dev
i
ce's
FCM
token
to
Google's
FCM
servers
.
Google
routes
the
not
i
f
i
cat
i
on
to
your
dev
i
ce
through
i
ts
global
i
nfrastructure
.
Google
acts
as
a
processor
on
our
behalf
for
th
i
s
purpose
.
5
.
2
Your
fac
i
l
i
ty
(controller)
The
fac
i
l
i
ty
that
l
i
censes
LenexaCARE
may
rece
i
ve
aggregated
and
i
nd
i
v
i
dual
records
of
alerts
,
acknowledgements
,
s
i
gn-
i
ns
and
other
aud
i
t
events
relat
i
ng
to
i
ts
own
staff
and
beds
.
5
.
3
Legal
requ
i
rements
We
may
d
i
sclose
i
nformat
i
on
when
requ
i
red
by
law
,
court
order
,
or
government
request
,
or
to
protect
the
safety
,
r
i
ghts
or
property
of
Lenexa
Med
i
cal
, i
ts
users
,
or
the
publ
i
c
.
6
.
Where
your
i
nformat
i
on
i
s
stored
and
transferred
The
App's
pr
i
mary
data
i
s
stored
i
n
the
same
AWS
reg
i
on
as
you
.
For
Austral
i
an
users
th
i
s
means
the
data
does
not
leave
Austral
i
a
at
rest
.
If
you
use
the
App
from
outs
i
de
Austral
i
a
,
your
i
nformat
i
on
w
i
ll
be
stored
i
n
the
AWS
reg
i
on
serv
i
ng
your
fac
i
l
i
ty
.
F
i
rebase
Cloud
Messag
i
ng
del
i
very
may
trans
i
t
Google's
global
i
nfrastructure
(
i
nclud
i
ng
servers
i
n
the
Un
i
ted
States)
on
i
ts
way
from
our
backend
to
your
dev
i
ce
.
Google
rel
i
es
on
the
Standard
Contractual
Clauses
approved
by
the
European
Comm
i
ss
i
on
and
on
equ
i
valent
transfer
mechan
i
sms
i
n
other
j
ur
i
sd
i
ct
i
ons
to
safeguard
such
transfers
.
7
.
How
long
we
keep
i
nformat
i
on
We
reta
i
n
i
nformat
i
on
for
as
long
as
we
have
a
contract
w
i
th
the
fac
i
l
i
ty
you
work
for
,
and
afterwards
as
follows
.
Category Retent
i
on
Backups
of
our
databases
are
reta
i
ned
for
35
days
through
Po
i
nt-
i
n-T
i
me
Recovery
,
after
wh
i
ch
they
are
unrecoverable
.
8
.
Your
r
i
ghts
Depend
i
ng
on
where
you
are
located
,
you
have
some
or
all
of
the
follow
i
ng
r
i
ghts
regard
i
ng
your
personal
i
nformat
i
on
.
Access
:
Ask
for
a
copy
of
the
personal
i
nformat
i
on
we
hold
about
you
.
Correct
i
on
/
rect
i
f
i
cat
i
on
:
Ask
us
to
correct
i
nformat
i
on
that
i
s
i
naccurate
or
i
ncomplete
.
Erasure
/
delet
i
on
:
Ask
us
to
delete
your
personal
i
nformat
i
on
.
We
may
decl
i
ne
i
f
we
are
requ
i
red
by
law
or
by
record-keep
i
ng
obl
i
gat
i
ons
to
reta
i
n
i
t
(
i
n
part
i
cular
,
aud
i
t-log
entr
i
es)
.
Restr
i
ct
i
on
and
ob
j
ect
i
on
:
Ask
us
to
restr
i
ct
,
or
ob
j
ect
to
,
how
we
process
your
i
nformat
i
on
.
Portab
i
l
i
ty
:
Ask
for
a
copy
of
your
i
nformat
i
on
i
n
a
portable
,
mach
i
ne-readable
format
.
Account
i
nformat
i
on
(ema
i
l
,
name
,
user
_i
d)
Deleted
w
i
th
i
n
14
bus
i
ness
days
of
the
fac
i
l
i
ty's
contract
end
i
ng
,
unless
reta
i
ned
for
the
aud
i
t
per
i
od
below
.
Dev
i
ce
tokens
(dev
i
ce
_i
d
,
FCM
token
,
OS
,
t
i
mezone)
Deleted
w
i
th
i
n
14
bus
i
ness
days
of
contract
end
or
s
i
gn-out
,
wh
i
chever
i
s
earl
i
er
.
Alerts
,
acknowledgements
,
snooze
rules
Deleted
w
i
th
i
n
14
bus
i
ness
days
of
contract
end
.
Frame
buffers
(sensor-data
cl
i
ps
i
n
S3)
Deleted
w
i
th
i
n
14
bus
i
ness
days
of
contract
end
.
Aud
i
t
log
Reta
i
ned
for
twelve
(12)
months
from
the
date
of
each
event
,
even
after
the
contract
ends
,
to
meet
aud
i
t
obl
i
gat
i
ons
.
After
twelve
months
,
aud
i
t
records
are
deleted
.
Authent
i
cat
i
on
refresh
token
(on
your
dev
i
ce)
30
days
from
last
use
,
or
unt
i
l
you
fully
s
i
gn
out
,
wh
i
chever
i
s
earl
i
er
.
Generated
v
i
deo
f
i
le
i
n
app
cache
24
hours
,
then
automat
i
cally
deleted
.
W
i
thdrawal
of
consent
:
Where
we
rely
on
your
consent
(for
example
,
to
send
push
not
i
f
i
cat
i
ons)
,
w
i
thdraw
that
consent
at
any
t
i
me
.
To
exerc
i
se
any
of
these
r
i
ghts
,
ema
i
l
.
We
respond
w
i
th
i
n
30
days
.
We
may
need
to
ver
i
fy
your
i
dent
i
ty
before
act
i
ng
on
a
request
.
If
we
cannot
resolve
your
concern
,
you
may
also
lodge
a
compla
i
nt
w
i
th
the
pr
i
vacy
regulator
i
n
your
j
ur
i
sd
i
ct
i
on
:
Austral
i
a
:
Off
i
ce
of
the
Austral
i
an
Informat
i
on
Comm
i
ss
i
oner
( OAIC
)
.
S
i
ngapore
:
Personal
Data
Protect
i
on
Comm
i
ss
i
on
( PDPC
|
Home
)
.
European
Econom
i
c
Area
/
Un
i
ted
K
i
ngdom
:
Your
local
superv
i
sory
author
i
ty
.
Cal
i
forn
i
a
,
USA
:
Cal
i
forn
i
a
Pr
i
vacy
Protect
i
on
Agency
or
Cal
i
forn
i
a
Attorney
General
.
9
.
Secur
i
ty
We
take
reasonable
steps
to
protect
the
i
nformat
i
on
we
hold
from
m
i
suse
,
loss
,
unauthor
i
sed
access
,
mod
i
f
i
cat
i
on
or
d
i
sclosure
.
Our
key
techn
i
cal
safeguards
i
nclude
:
All
network
commun
i
cat
i
on
between
the
App
and
our
backend
uses
TLS
1
.
2
or
h
i
gher
.
Your
authent
i
cat
i
on
refresh
token
and
dev
i
ce
i
dent
i
f
i
er
are
stored
on
your
dev
i
ce
i
n
the
operat
i
ng-system
keycha
i
n
(
i
OS)
or
Andro
i
d
Keystore
,
wh
i
ch
use
hardware-backed
encrypt
i
on
where
ava
i
lable
.
AWS
calls
from
the
App
are
s
i
gned
us
i
ng
AWS
S
i
gnature
Vers
i
on
4
w
i
th
short-l
i
ved
(approx
i
mately
one-hour)
temporary
credent
i
als
i
ssued
by
Amazon
Cogn
i
to
.
Our
DynamoDB
tables
have
delet
i
on
protect
i
on
and
35-day
po
i
nt-
i
n-t
i
me
recovery
enabled
.
Our
aud
i
t
log
i
s
append-only
and
i
mmutable
.
No
secur
i
ty
measure
i
s
perfect
.
If
we
become
aware
of
a
personal
data
breach
that
i
s
l
i
kely
to
result
i
n
a
s
i
gn
i
f
i
cant
r
i
sk
of
harm
,
we
w
i
ll
not
i
fy
affected
users
and
the
relevant
regulator
w
i
thout
undue
delay
and
i
n
l
i
ne
w
i
th
our
legal
obl
i
gat
i
ons
(
i
nclud
i
ng
the
Not
i
f
i
able
Data
Breaches
scheme
under
the
Pr
i
vacy
Act
1988
i
n
Austral
i
a)
.
10
.
Perm
i
ss
i
ons
the
App
requests
on
your
dev
i
ce
The
App
requests
the
follow
i
ng
operat
i
ng-system
perm
i
ss
i
ons
only
when
needed
:
Not
i
f
i
cat
i
ons
.
To
del
i
ver
real-t
i
me
alert
push
not
i
f
i
cat
i
ons
.
You
can
revoke
th
i
s
perm
i
ss
i
on
i
n
your
dev
i
ce
sett
i
ngs
.
software@lenexamed
i
cal
.
com
Photo
l
i
brary
(wr
i
te
only)
.
To
save
the
generated
short
v
i
deo
f
i
le
when
you
tap
"Save
to
gallery"
.
The
App
cannot
read
ex
i
st
i
ng
photos
on
your
dev
i
ce
.
The
App
does
not
request
camera
,
m
i
crophone
,
locat
i
on
,
contacts
,
calendar
,
SMS
or
call
perm
i
ss
i
ons
.
11
.
Ch
i
ldren
The
App
i
s
i
ntended
for
use
by
profess
i
onal
staff
aged
16
or
older
.
We
do
not
know
i
ngly
collect
personal
i
nformat
i
on
from
ch
i
ldren
under
16
.
If
you
bel
i
eve
we
have
collected
i
nformat
i
on
from
a
ch
i
ld
,
please
contact
us
and
we
w
i
ll
delete
i
t
.
12
.
Jur
i
sd
i
ct
i
on-spec
i
f
i
c
terms
12
.
1
Austral
i
an
users
We
comply
w
i
th
the
Austral
i
an
Pr
i
vacy
Pr
i
nc
i
ples
set
out
i
n
the
Pr
i
vacy
Act
1988
(Cth)
.
Sens
i
t
i
ve
i
nformat
i
on
,
where
i
t
appl
i
es
, i
s
collected
only
w
i
th
your
consent
and
only
where
reasonably
necessary
for
the
App
to
funct
i
on
as
an
alert
i
ng
tool
.
12
.
2
S
i
ngapore
users
We
comply
w
i
th
the
Personal
Data
Protect
i
on
Act
2012
(PDPA)
.
Our
Data
Protect
i
on
Off
i
cer
can
be
contacted
at
.
Sens
i
t
i
ve
i
nformat
i
on
i
s
collected
only
w
i
th
your
consent
and
only
where
reasonably
necessary
for
the
App
to
funct
i
on
as
an
alert
i
ng
tool
.
12
.
3
European
Econom
i
c
Area
and
Un
i
ted
K
i
ngdom
users
We
rely
on
the
follow
i
ng
legal
bases
under
the
General
Data
Protect
i
on
Regulat
i
on
(GDPR)
and
the
UK
GDPR
:
Performance
of
a
contract
(w
i
th
your
fac
i
l
i
ty)
for
account
and
alert-del
i
very
funct
i
ons
.
Leg
i
t
i
mate
i
nterests
(del
i
ver
i
ng
pos
i
t
i
onal
alerts
safely
,
ma
i
nta
i
n
i
ng
an
aud
i
t
tra
i
l
,
secur
i
ng
our
serv
i
ce)
.
Legal
obl
i
gat
i
on
(aud
i
t-log
retent
i
on
for
operat
i
onal
accountab
i
l
i
ty)
.
Consent
(push
not
i
f
i
cat
i
ons
,
photo-l
i
brary
save)
.
Personal
data
i
s
transferred
to
AWS
and
to
Google's
global
FCM
i
nfrastructure
on
the
bas
i
s
of
the
European
Comm
i
ss
i
on's
Standard
Contractual
Clauses
(and
the
UK
addendum
where
appl
i
cable)
.
software@lenexamed
i
cal
.
com
12
.
4
Cal
i
forn
i
a
users
If
you
are
a
Cal
i
forn
i
a
res
i
dent
,
the
Cal
i
forn
i
a
Consumer
Pr
i
vacy
Act
(CCPA)
and
the
Cal
i
forn
i
a
Pr
i
vacy
R
i
ghts
Act
(CPRA)
g
i
ve
you
r
i
ghts
to
know
,
delete
,
correct
and
l
i
m
i
t
the
use
of
your
personal
i
nformat
i
on
,
and
to
opt
out
of
"sale"
or
"shar
i
ng"
of
personal
i
nformat
i
on
.
We
do
not
sell
or
share
your
personal
i
nformat
i
on
for
cross-context
behav
i
oural
advert
i
s
i
ng
.
To
exerc
i
se
your
r
i
ghts
,
ema
i
l
.
13
.
Changes
to
th
i
s
pol
i
cy
We
may
update
th
i
s
Pr
i
vacy
Pol
i
cy
from
t
i
me
to
t
i
me
.
If
we
make
a
mater
i
al
change
,
we
w
i
ll
not
i
fy
users
through
the
App
or
by
ema
i
l
,
and
w
i
ll
update
the
"Effect
i
ve
date"
at
the
top
of
th
i
s
document
.
14
.
Contact
us
For
any
pr
i
vacy
enqu
i
ry
,
request
to
exerc
i
se
your
r
i
ghts
,
or
compla
i
nt
,
please
contact
:
Lenexa
Med
i
cal
Pty
Ltd
Ema
i
l
:
Address
:
Level
1/70
Adam
St
,
Burnley
VIC
3121
,
Austral
i
a
software@lenexamed
i
cal
.
com
software@lenexamed
i
cal
.
com