Privacy
Privacy Policy
How we handle and protect your personal data.
What we will not share
Unless you agree, we will not share your conversation interactions with Serenio, such as what you write or the path you take in a conversation.
Interactions with third-party services
Our services may connect with third parties, such as helplines or other resources. Any information shared with or collected by third parties is governed by that third party's terms and privacy policy. We are not responsible for third parties' handling of personal data related to these resources.
De-identified and/or aggregated data
We may use your personal data to create de-identified and/or aggregated data, such as approximate location, information about the device you use to access our services, conversation trends, or other analytics. De-identified and/or aggregated data is not personal data, and we may use and share it in accordance with applicable law, for example with academic partners. Even when de-identified, we will not share your conversation records with Serenio without your consent.
How is my personal data protected?
We work to implement security measures designed to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. This may include, as applicable: following hospital-grade security policies and procedures to protect sensitive user data, in line with HIPAA requirements including the Privacy and Security Rules; using cloud-based infrastructure designed to reduce our data footprint; encrypting all personal data, both at rest and in transit; storing sensitive personal data securely in dedicated environments to ensure separation and clear access control; using technical network controls such as multi-factor authentication and deny-all/allow-by-exception to maintain controlled access; conducting and responding to penetration tests, vulnerability assessments, code reviews and internal compliance reviews; maintaining our business continuity, disaster recovery and incident response plans; and allowing employees to access personal data only where relevant to their job duties.
Despite these efforts, no security measure is perfect, and no method of data transmission or storage can guarantee against unauthorized disclosure or misuse. We therefore cannot ensure or warrant the security of any personal data you provide to us. To the maximum extent permitted by applicable law, we accept no liability for unauthorized access, use, disclosure or loss of personal data.
How long do you store my personal data?
We store personal data to provide you with a personalized service experience based on your past interactions, and for the other reasons described above. We retain the personal data we collect until you stop using our services, or as needed to fulfil the purposes of collection, provide our services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable law. To learn more about our data retention practices, please contact us.
What rights do I have?
Anyone who uses the service can access, correct or delete their personal data, wherever they live or are located. In addition, under certain data protection laws, individuals may have rights over their personal data, which may include, as applicable: the right of access to the personal data we hold about you and how we use it; the right to rectification of inaccurate or incomplete personal data, including protected health information (PHI); the right to request erasure in certain circumstances; the right to restrict or object to our processing in certain circumstances; the right to data portability; the rights to obtain copies of, receive confidential communications of, restrict the use or disclosure of, and obtain an accounting of disclosures of your PHI; the right to designate a personal representative; the right to withdraw consent; and the right to obtain a paper copy of this Privacy Policy.
We will handle your request in accordance with applicable law. Please note that we will need you to take steps to verify your identity. If you wish to exercise any of these rights, please contact us.
How do I control my personal data?
If you have feedback or questions about any aspect of how we collect, share or use your personal data, please contact us. If your personal data is governed by the applicable data protection laws of the European Economic Area, Switzerland or the United Kingdom, you have the right to lodge a complaint with a competent supervisory authority if you believe our processing violates applicable law. You cannot opt out of certain important communications, such as updates to our terms or this Privacy Policy.
- SMS: follow the instructions in the messages you receive, or contact us.
- Push notifications: we may send push notifications through one of our mobile apps; opt out by changing your device settings.
- Do Not Track (DNT): we honor DNT on our website. DNT preferences do not apply to mobile apps.
- Cookies and similar technologies: you can stop, limit or delete certain cookies depending on your browser or device permissions, on each browser and device. We use cookies only on our website, not in any mobile app. If you adjust your preferences, some services may not function properly.
What are my responsibilities?
You are responsible for helping protect your personal data by securing your device, email and password. For best practices, see the U.S. Federal Trade Commission (FTC) guidance on protecting your privacy on apps and keeping your personal information secure.
Protecting children's information. The service is not directed to children (defined as under 13, or another age as required by local law), and we do not knowingly collect children's personal data. If you discover that your child has provided personal data to us without your consent, please contact us. If we learn that we have collected a child's personal data in violation of applicable law, we will delete that data (unless legally required to retain it) and close the child's account.
Third parties. The service may contain links to third-party websites or apps not covered by this Privacy Policy. We are not responsible for their privacy practices or content. Providing personal data to them is at your own risk.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you to the extent permitted by applicable law, generally by posting the updated policy on our website or app before the changes take effect, and in some cases by email. The updated terms supersede previous terms and take effect immediately upon posting, except as otherwise required or permitted by law. Continuing to use our services indicates your agreement to the updated Privacy Policy.
Contact us
If you have any questions, comments or complaints about this Privacy Policy or our information-handling practices, please contact Serenio AI Limited (company registration number: 3299059), email support@serenio.ai.
Last updated: 22 August 2023
我們不會分享
除非您同意,否則我們不會分享您與 Serenio 的對話互動,例如您所寫的內容或您在對話中的路徑。
與第三方服務的互動
我們的服務可能與第三方建立連接,例如求助熱線或其他資源。與第三方共享或由第三方收集的任何信息均受第三方的條款和隱私政策約束。我們對第三方處理與這些資源相關的個人數據概不負責。
去標識化和/或聚合數據
我們可能使用您的個人數據來創建去標識化和/或聚合數據,例如大約的位置信息、您用於訪問我們服務的設備信息、對話趨勢的信息或其他分析。去標識化和/或聚合數據不是個人數據,我們可以根據適用法律使用和分享這些數據,例如與學術合作夥伴。即使去標識化,我們也不會在未經您同意的情況下與 Serenio 分享您的對話記錄。
我的個人數據受到哪些保護?
我們努力實施安全措施,旨在避免意外或非法破壞、損失、更改、未經授權的披露或訪問個人數據。這可能包括(根據實際情況):遵循醫院級別的安全政策和程序以保護敏感用戶數據,遵守 HIPAA 規定,包括隱私和安全規定;使用基於雲的基礎設施,旨在減少我們的數據足跡;對所有個人數據進行加密,無論是在休息時還是在傳輸過程中;將敏感個人數據安全地存儲在專用環境中,以確保分離和清晰的訪問控制;使用技術網絡控制,例如多因素身份驗證和拒絕所有/例外允許;進行並回應滲透測試、漏洞評估、代碼審查和內部合規審查;維護我們的業務連續性、災難恢復和事件響應計劃;僅在與工作職責相關的情況下允許員工訪問個人數據。
儘管有這些努力,但沒有任何安全措施是完美的,也沒有任何數據傳輸或存儲方法能保證防止未經授權的披露或濫用。因此,我們無法確保或擔保您向我們提供的任何個人數據的安全性。在適用法律允許的最大範圍內,我們不接受有關未經授權訪問、使用、披露或個人數據損失的責任。
您存儲我的個人數據多久?
我們儲存個人數據,以便根據您過去的互動為您提供個性化的服務體驗,以及為了上述其他原因。我們會保留所收集的個人數據,直到您停止使用我們的服務,或根據需要為達到收集目的、提供我們的服務、解決爭議、建立法律辯護、進行審計、追求合法業務目的、執行我們的協議以及遵守適用法律。如需了解更多有關我們的數據保留實踐的信息,請與我們聯繫。
我有哪些權利?
任何使用服務的人都可以訪問、更正或刪除他們的個人數據,無論他們住在哪裡或身處何地。此外,在某些數據保護法下,個人可能對其個人數據享有權利,這些權利可能包括(根據實際情況):訪問權、更正權(包括受保護的健康信息 PHI)、在某些情況下要求刪除的權利、限制或反對處理的權利、數據可攜權,以及就受保護健康信息(PHI)獲取副本、以替代方式接收保密通信、要求限制使用或共享、獲取披露記錄、指定個人代表、撤回同意,以及獲得本隱私政策紙本副本的權利。
我們將根據適用法律處理您的請求。請注意,我們需要您採取措施以驗證您的身份。如果您希望行使上述任何權利,請與我們聯繫。
我如何控制我的個人數據?
如果您對我們收集、共享或使用您的個人數據的任何方面有反饋或疑問,請與我們聯繫。如果您的個人數據受歐洲經濟區、瑞士或英國適用數據保護法的管轄,且您認為我們的處理違反了適用法律,您有權向主管監管機構提出投訴。您無法退出某些類型的重要通信,例如對我們條款或本隱私政策的更新。
- 短信:按照您收到的短信中的指示,或與我們聯繫。
- 推送通知:我們可能透過我們的移動應用程序向您發送推送通知,可透過更改設備設置選擇退出。
- 不跟踪(DNT):我們在網站上遵守 DNT。DNT 首選項不適用於移動應用程序。
- Cookie 和類似技術:您可以視瀏覽器或設備許可,停止、限制或刪除我們使用的某些 Cookie,且須在每個瀏覽器和設備上分別操作。我們僅在網站上使用 Cookie,而非任何移動應用程序。如果您調整首選項,部分服務可能無法正常運行。
我有什麼責任?
您有責任透過保護您的設備、電子郵件和密碼,幫助保護您的個人數據。有關最佳實踐,請參閱美國聯邦貿易委員會(FTC)關於如何保護您在應用程序上的隱私與個人信息安全的指南。
保護兒童信息。服務不針對兒童(定義為 13 歲以下或當地法律要求的其他年齡),我們不會故意收集兒童的個人數據。如果您發現您的孩子未經您的同意向我們提供了個人數據,請與我們聯繫。如果我們得知違反適用法律收集了兒童的個人數據,我們將刪除這些數據(除非有法律義務保留),並關閉兒童的帳戶。
第三方。服務可能包含未涵蓋本隱私政策的第三方網站或應用程序的鏈接。我們不對其隱私實踐或內容負責,向其提供個人數據將由您自行承擔風險。
本隱私政策的變更
我們可能會不定期更新本隱私政策。如果我們進行重大更改,將在適用法律允許的範圍內通知您,通常會在變更生效前於我們的網站或應用上發布更新後的政策,某些情況下會以電子郵件通知。更新後的條款將取代之前的條款,並於發布時立即生效(法律另有要求或允許者除外)。繼續使用我們的服務即表示您同意更新後的隱私政策。
聯繫我們
如果您對本隱私政策或我們的信息處理做法有任何問題、意見或投訴,請聯繫 Serenio AI Limited(公司註冊號碼:3299059),電子郵件 support@serenio.ai。
本隱私政策的最後更新日期為 2023 年 8 月 22 日。