Privacy Policy
NUVO GROUP INVU SYSTEM PRIVACY POLICY
Last Updated: February 2024
NUVO GROUP LTD., a company organized under the laws of the State of Israel (together with its subsidiaries, affiliates, and/or related companies) (“Company”, “our”, “we” or “us”), provides authorized patients and providers (“you”, “User”, “your”) access to its Invu Pregnancy Remote MonitoringSystem (“Invu System”), which is comprised of a proprietary app(the “App”), monitoring band (the “Band”) and web-based processing platform (“Platform”).
As we are committed to protecting your rights to privacy, and we make available this Privacy Policy (the "PrivacyPolicy") to describe our practices regarding the information we may collect or to which we may have access, through your use of the Invu System and the manner in which we may use such information, and the choices and rights available to you.
For purposes of this Privacy Policy, a user may be the user who is prescribed the Invu System or the health provider (the “Provider”)who prescribes the Invu System.
PLEASE READ THIS PRIVACY POLICY CAREFULLY BEFORE ACCESSING AND USING INVU SYSTEM. BY ACCESSING OR USING ANY FEATURE WITHIN THE INVU SYSTEM, YOU ARE ACCEPTING THE PRACTICES AND POLICIES DESCRIBED IN THIS PRIVACY POLICY. IF YOU DISAGREE TO ANY TERM PROVIDED HEREIN, YOU MAY NOT ACCESS OR USE ANY COMPONENT OF THE INVU SYSTEM.
A. WHAT INFORMATION DO WE COLLECT?
Personal information is individually identifiable information, namely information that identifies an individual or may with reasonable efforts or together with additional information we have access to, enable the identification of an individual, or may be of a private or sensitive nature relating to an identified or identifiable natural person. Identification of an individual also includes the association of such individual with a persistent identifier such as a name, an identification number, persistent cookie identifier etc. Personal information does not include information that has been anonymized or aggregated; provided, that, such information can no longer be used to identify a specific natural person. Please refer to Section G below for the Health Data we collect and how we use such information.
We collect personal information from you when you use or interact with the Invu System, including:
- Personal information you provide to us when you use the Invu System. We collect personal information from or about you when you use or access the Invu System, provide us information on a web form or other text field, update or add information to your account, or through correspondence that you exchange with us from time to time (i.e., via email, chat, etc.). More specifically, we collect and use the following categories and types of personal information when you use the Invu System:
- Contact information such as your name, email and physical addresses, or telephone number when your Provider completes our online form, registers for an account with us or otherwise when your Provider updates your accounts details.
- Information we otherwise collect during a monitoring session using the Invu System.
- The contents of your and/or your Provider’s interactions with our customer/technical support personnel, which may include text/video/audio recording and transcripts of such communications.
- Shipping and delivery information used by us and/or our service providers to deliver the Invu Band.
- Information your Provider provides in the Invu System to personalize your system interface, such as age, preferred language, preferences, etc.
- Information that you may provide to us directly.
- Health Data, as described below.
B. HOW WE COLLECTION YOUR INFORMATION
- Ancillary Tools. You may provide us information through your use of certain external tools, features and applications which are associated with the Invu System and provisioned by Nuvo.
- Information Mandated by Applicable Law. Information we are required or otherwise authorized to collect under applicable laws to authenticate or identify you or to verify the information we have collected from you via the Invu System.
- Electronic Medical Records. If you’re a Provider, we allow you to connect your electronic medical records (“EMR”) to the INVU System through the use of one or more APIs supplied by Nuvo. The information transmitted to/from the Invu System and your EMR shall constitute personal information under this PrivacyPolicy, and may be used by Nuvo in accordance with the provisions contained hereunder. If Provider seeks to impose any restrictions or limitations on Nuvo in respect of Nuvo’s use of thePersonal Information supplied to it, such restrictions must be agreed to in advance and in writing by Provider and Nuvo.
- Device Information. We collect information from and about the computers, phones, tablets and other web-connected devices you use that integrate with the Invu System, and we combine this information across different devices you use. For example, we use information collected about your use of the Invu App on your mobile phone to better personalize the content or features made available to you. Information we obtain from these devices includes:
- Device attributes: information such as the operating system, hardware and software versions, battery level, signal strength, available storage space, browser type, app and file names and types, and plugins.
- Device operations: information about operations and behaviors performed on the device, such as whether a window is foregrounded or backgrounded, or mouse movements (which can help distinguish humans from bots).
- Identifiers: unique identifiers, device IDs, and other identifiers.
- Device signals: Bluetooth signals, and information about nearby Wi-Fi access points, beacons, and cell towers.
- Data from device settings: information you allow us to receive through device settings you turn on, such as access to your GPS location.
- Network and connections: information such as the name of your mobile operator orISP, language, time zone, mobile phone number, IP address, connection speed and, in some cases, and information about other devices that are nearby or on your network.
- Cookie data: data from cookies stored on your device, including cookie IDs and settings. Learn more about how we use cookies, please review our Cookie Policy below.
We perform such automatic collection through use of cookies, web beacons, unique identifiers, and similar technologies which allow us to collect information about the pages and screens you view, the links you click, and other actions you take when using the Invu App. For more information about our use of these technologies, and how to control them, see our CookiesPolicy.
C. WHY WE COLLECT AND PROCESS PERSONAL INFORMATION
We collect, process and use User’s information for the purposes described in this Privacy Policy, based at least on one of the following legal grounds:
- When Performing the Services: We collect and process your Personal Information to provide you with the functionality from the Invu System, following your acceptance of our Terms of Use and this Privacy Policy.
- Legitimate interests: We process your information for our or others’ legitimate interest while applying appropriate safeguards that protect your privacy. Our legitimate interests may span things like detecting, preventing, or otherwise addressing fraud, abuse, security, usability, functionality or technical issues with our services, protecting against harm to the rights, property or safety of our properties, users, or the public as required or permitted by law; enforcing legal claims, including investigation of potential violations of this PrivacyPolicy; to comply and/or fulfill our obligations under applicable laws, regulations, guidelines, industry standards and contractual requirements, legal process, subpoena or governmental request; and in accordance with our Terms of Use.
- Marketing Materials: We may ask for your consent to deliver marketing offers and related communications. You will have the right to decline or otherwise withdraw your consent at any time.
We may also access and use your information for any of the following internal purposes:
- To maintain and improve the Invu System;
- To develop new services and features for you and our INVU users;
- To send you updates, notices, notifications, announcements, and additional information related to the Invu System;
- To be able to manage your account and provide you with customer support and technical assistance;
- To create cumulative statistical data and other cumulative information and/or other conclusive information that isnon-personal, in which we might make use, in order to operate and improve the Invu System;
- To verify and authenticate your eligibility to use the Invu System;
- To prevent, detect, mitigate, and investigate fraud, security breaches or other potentially prohibited or illegal activities, including any breaches of this Privacy Policy or of our Terms of Use;
- To protect you and other users of the INVU system for loss prevention, to protect against fraud and other illegal acts or content; and
- To comply with any applicable rule or regulation and/orresponse or defend against legal proceedings.
We do not use algorithms or profiling to make any decision that would significantly affect you without the opportunity for human review. We also do not use or disclose sensitive personal data for any purposes that would require a user to exercise a right to limit processing according to California law.
In addition, we retain personal data only for so long as necessary to fulfill the purposes for which it was collected, including as described in this Privacy Policy or as required by law.
D. WHERE DO WE PROCESS AND STORE USER’S PERSONAL INFORMATION?
Information regarding the Users will be maintained, processed and stored by us and our authorized affiliates and service providers in various locations around the world, including, without limitation, the United States and Israel. Any and all personal information that we collect from our users is maintained in secured cloud storage environments provisioned by third party cloud providers.
It is our policy, irrespective of the jurisdictions wherein our Users are located, to maintain all User-supplied data in secure environments provisioned by third parties that: (i) have assured us of the safeguards which they implement to protect your privacy, or (ii) hold and process such information on our behalf in those jurisdictions that we’ve expressly approved. As and when we’ve determined it is necessary to comply with applicable laws and regulations, we have entered into business associate agreements and/or data processing agreements with such third parties.
E. TO WHOM WE SHARE PERSONAL INFORMATION
We may share your personal information with third parties (or otherwise allow them access to it) only in the following manners and circumstances:
- Providers: We may share your personal information with the Provider who prescribed the Invu System to you.
- Third Party Services: We partner with a number of third party service providers, whose services and solutions complement, facilitate and enhance our own. These include hosting, data and cyber security services, fraud detection and prevention services, merchant processing, shipping, postal and delivery services, website and mobile app functionality, manufacturing services, e-mail and text message distribution and monitoring services, analytics services, customer support and call center services, as well as our business, legal and financial advisors, and others (collectively, "Third Party Service Providers").Each such Third-Party Service Provider may receive or otherwise have access to your personal information through your use of our Services, and may only use your personal information for such purpose(s) as expressly authorized by us.Such disclosure or access is strictly subject to the recipient's or user's undertaking of confidentiality and appropriate safeguards obligations, as well as the prevention of any independent right to use your personal information, subject to applicable law.
- Governmental/Law Enforcement Agencies and Legal Requests or Duties: We may disclose or otherwise allow access to Personal Information pursuant to a legal requirement or request, such as a subpoena, search warrant or court order, or in compliance with applicable laws and regulations. Such disclosure or access may occur with or without notice to you, if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.
- Protecting Rights and Safety: We may share your personal information with others, with or without notice to you, if we believe in good faith that this will help protect the rights, property or personal safety of our Company, of any of our Users, or any members of the general public.
- Our Affiliated Companies: We may share personal information internally within our affiliates for the purposes described in this Privacy Policy. In addition, should we or any of our affiliates undergo any change in control, including by means of merger, acquisition or purchase of substantially all of our assets, your personal information may be shared with the parties involved in such event. If we believe that such change in control might materially affect your personal information then stored with us, we will notify you of this event and the choices you may have via e-mail and/or prominent notice on our Website.
F. YOUR RIGHTS
You can make certain choices regarding our collection and use of the personal information you share with us by emailing the Company at privacy@nuvocares.com. By way of example, you may request (i) access to the personal information we’ve collected from/about you, (ii) that updates are made to your personal information, (iii) that we cease using your personal information to contact you, and (iv) we delete the personal information about you in our records. We will undertake to respond to your request within 30 days of receipt thereof. In some cases, your ability to access or control your personal information will be limited, as required or permitted by applicable law. If that should happen, the Company will notify you accordingly. How you can access or control your personal information will also depend on your continued use of the Invu System. For example, if you ask us to case collecting your personal information and/or delete your personal information, we may suspend or terminate your right to use the Invu System. We will retain your information for as long as your account is active or as needed to provide you access to the Invu System. We will also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and to enforce our agreements.
For the removal of doubt, we expressly reserve the right to transfer, share or otherwise use non-personally identifiable information(e.g., anonymous, aggregated information) in our sole discretion and without the need for further approval.
G. PHI/PERSONAL DATA
We are required by law to maintain the privacy of your “Health Data”(which is known as protected health information or “PHI” under the HealthInsurance Portability and Accountability Act of 1996, as amended (“HIPAA”) and sensitive personal data under EU Regulation 2016/679, also known as the General Data Protection Regulation (“GDPR”)),and to provide you with notice of our legal duties and privacy practices with respect to your Health Data. Health Data, for purposes of this Agreement, is information that may identify you and that relates to your past, present, or future physical or mental health or condition, the provision of health care products and services to you or payment for such services. This Notice describes how we may use and disclose Health Data about you, as well as how you obtain access to such Health Data. This Notice also describes your rights with respect to your Health Data. We are required by the HealthInsurance Portability and Accountability Act of 1996, as amended (“HIPAA”)to provide this Notice to you.
- Treatment. We may use and disclose your Health Data to provide and coordinate the treatment, medications and services you receive. For example, we may disclose Health Data to doctors, nurses, technicians and other personnel involved in your health care. We may also disclose your Health Data with other third parties, such as hospitals, other pharmacies and other health care facilities and agencies to facilitate the provision of health care services, medications, equipment and supplies you may need. This helps to coordinate your care and make sure that everyone who is involved in your care has the information that they need about you to meet your health care needs.
- Research & Development. We may use and disclose your PHI to our research partners who are committed to furthering research in the areas of pregnancy remote monitoring, improving treatment protocols and other related areas which are pursued by Nuvo.
- Payment. We may use and disclose your Health Data in order to obtain payment for the health care products and services that we provide to you and for other payment activities related to the services that we provide. For example, we may contact your insurer, pharmacy benefit manager or other health care payor to determine whether it will pay for health care products and services you need and to determine the amount of your co-payment. We will bill you or a third-party payor for the cost of health care products and services we provide to you. The information on or accompanying the bill may include information that identifies you, as well as information about the services that were provided to you or the medications you are taking. We may also disclose your Health Data to other health care providers or HIPAA covered entities who may need it for their payment activities.
We may also use and disclose your Health Data without your prior authorization for the following purposes:
- Business Associates/Processors. We may contract with third parties to perform certain services for us, such as billing services, copy services, hosting services or other consulting services. These Third Party Service Providers, referred to as sub-contractors or sub-processors, may need to access your Health Data to perform services for us. They are required by contract and law to protect your Health Data and only use and disclose it as necessary to perform their services for us.
- To Communicate with Individuals Involved in Your Care or Payment for Your Care. We may disclose to a family member, other relative, close personal friend, or any other person you identify, Health Data directly relevant to that person's involvement in your care or payment related to your care. Additionally, we may disclose Health Data to your "personal representative." If a person has the authority by law to make health care decisions for you, we will generally regard that person as your "personal representative" and treat him or her the same way we would treat you with respect to your Health Data.
- Food and Drug Administration ("FDA"). We may disclose to persons under the jurisdiction of theFDA, Health Data relative to adverse events with respect to drugs, foods, supplements, products and product defects, or post-marketing surveillance information to enable product recalls, repairs, or replacement.
- Worker's Compensation. To the extent necessary to comply with law, we may disclose your Health Data to worker's compensation or other similar programs established by law.
- Public Health. We may disclose your Health Data to public health or legal authorities charged with preventing or controlling disease, injury, or disability, including the FDA. In certain circumstances, we may also report work-related illnesses and injuries to employers for workplace safety purposes.
- Law Enforcement. We may disclose your Health Data for law enforcement purposes as required or permitted by law for example, in response to a subpoena or court order, in response to a request from law enforcement, and to report limited information in certain circumstances.
- As Required by Law. We will disclose your Health Data when required to do so by national, federal, state or local law.
- Health Oversight Activities. We may disclose your Health Data to an oversight agency for activities authorized by law. These oversight activities include audits, investigations, inspections, and credentialing, as necessary for licensure and for the government to monitor the health care system, government programs and compliance with civil rights laws.
- Judicial and Administrative Proceedings. If you are involved in a lawsuit or a dispute, we may disclose your Health Data in response to a court or administrative order. We may also disclose your Health Data in response to a subpoena, discovery request, or other lawful process instituted by someone else involved in the dispute, but only if efforts have been made, either by the requesting party or us, to first tell you about the request or to obtain an order protecting the information requested.
Your Health Information Rights:
- Request a restriction on certain uses and disclosures of HealthData. You have the right to request additional restrictions on our use or disclosure of your Health Data by sending a written request to privacy@nuvocares.com. We reserve the right to submit your request to your Provider for confirmation and authorization before implementing any such restrictions.
- Inspect and obtain a copy of Health Data. Subject to a limited number of exceptions, you have the right to access and obtain a copy of the Health Data that we maintain about you. If we maintain an electronic health record containing your Health Data, you have the right to request to obtain the Health Data in an electronic format. To inspect or obtain a copy of your Health Data, you must send a written request to privacy@nuvocares.com. You may ask us to send a copy of yourHealth Data to other individuals or entities that you designate. We may deny your request to inspect and copy in certain limited circumstances. If you are denied access to your Health Data, you may request that the denial be reviewed.
- Request an amendment of Health Data. If you feel that the Health Data we maintain about you is incomplete or incorrect, you may request that we amend it. To request an amendment, you must send a written request to privacy@nuvocares.com. You must include a reason that supports your request. We reserve the right to submit your request to your Provider for confirmation and authorization. If we deny your request for an amendment, we will provide you with a written explanation of why we denied it.
- Receive an accounting of disclosures of Health Data. With the exception of certain disclosures, you have aright to receive a list of the disclosures we have made of your Health Data, inthe six years prior to the date of your request, to entities or individuals other than you. To request an accounting, you must submit a request in writing to privacy@nuvocares.com. Your request must specify a time period.
- Notification of a Breach. You have a right to be notified following a breach of your unsecured Health Data, and we will notify you in accordance with applicable law.
H. MOBILE COMMUNICATIONS
- By providing us with your mobile phone number, or by sending an SMS (containing a pre-designated number or word) to a phone number that we indicate, you are expressly opting-in to receive telephone calls to your mobile phone or text messages from us, some of which may be considered marketing and may be delivered by us using auto-dialer systems/technologies. You represent that you are the owner or authorized user of the mobile phone number that you supplied to us, and that you are authorized to approve the applicable charges and rates resulting from such SMS and/or MMS messages incurred by such device. Message and data rates may apply. You (and not Assured Allies) will be responsible for all messaging and data charges that may apply. Standard messaging rates apply to your entry or submission message to any Assured Allies text message service, our confirmation and all subsequent text message correspondence. Please contact your wireless carrier for information about your messaging and data plans. Your consent to receive text messages is not a condition of purchase. Carriers are not liable for delayed or undelivered messages. Message frequency may vary.
- Data obtained from you in connection with our mobile marketing programs may include your cell phone number, your carrier’s name and the date/time/content of any text messages that you send us. We reserve the right to use this data in the same manner and for the same purpose(s) as other data that we may collect in accordance with this Privacy Policy, including without limitation, in order to provide the services you request of us, and to otherwise operate, develop and improve our products and services.
- You can opt-out of receiving marketing-related text messages from us at any time by texting “STOP” (or some other SMS message designated by us) from the mobile device receiving the messages. If you choose to opt-out, you will be unsubscribed from our marketing text messaging program. You will receive one SMS that confirms you have successfully opted-out. After that you will receive no further messages for this system unless/until you opt-in again. For additional help, see our communication instructions below.
- Please know that even if you opt-out of receiving marketing-oriented text messages from us, we may still contact you via text message or phone call for transactional or informational purposes regarding your enrollment and use of our Offerings. Some examples are contacts for customer service, product information, service or reminder notices. Moreover, we reserve the right, at all times, to disclose any mobile messaging data you share with us as necessary to satisfy any law, regulation or governmental requests, to avoid liability and/or to protect our rights or property.
I. MINORS
To use the Invu System, you must be over the age of 18. Therefore, we do not knowingly collect personal information from minors under the age of 18 and do not wish to do so.
We reserve the right to request proof of age at any stage so that we can verify that minors under the age of eighteen (18) are not using the Invu System. If we learn that we have collected personal information from a user under 18 years of age, we will delete that information as quickly as possible. If you believe that we might have any such information, please contact us at privacy@nuvocares.com.
J. INFORMATION SECURITY
We take great care in implementing and maintaining the security of the Invu System. We employ industry standard procedures and policies to ensure the protection of personal information, and to prevent unauthorized use of any such information. Among other means we use Secure Socket Layer (SSL) technology, which creates an encrypted link between our web server and your browser, and provides a secured path of communication to ensure the information remains protected and private. Please note however, that regardless of the measures we take and the efforts we make, we cannot and do not guarantee the absolute protection and security of any personal information.
K. DATA PROCESSING AGREEMENT
If required by applicable law, the processing of your personal data shall be subject to this data processing agreement.
L. UPDATES TO THIS PRIVACY POLICY
From time to time, we may change the terms of thisPrivacy Policy. Changes will take effect once they are posted online and by accessing and/or using the Services after we make any such changes to this Privacy Policy, and you are deemed to have accepted such changes. If you do not agree with any of the amended terms, you must avoid any further use of theProperties and/or the Services provided thereon.
M. CALIFORNIA /DELAWARE “DO NOT TRACK DISCLOSURES”
California and Delaware law require us to indicate whether we honor “Do Not Track” settings in your browser concerning targeted advertising. Assured Allies adheres to the standards set out in this PrivacyPolicy and does not monitor or respond to Do Not Track browser requests.
N. GENERAL INFORMATION
This Privacy Policy, its interpretation, and any claims and disputes related hereto, shall be governed by the laws of theState of Israel. All such claims and disputes that you may wish to assert against the Company shall be exclusively submitted for adjudication in theSuperior Courts of Tel Aviv/Jaffa. The foregoing notwithstanding, if the Company shall seek equitable relief to enforce its rights under this Privacy Policy arising from your breach or alleged breach, the Company may do so in any court of competent jurisdiction.
O. HAVE ANY QUESTIONS?
Nuvo takes your privacy questions seriously. A dedicated team always reviews your inquiry(s)to determine how best to respond to your question or concern, including those inquiries received in response to an access or download request. In most cases, all substantive contacts receive a response within ten days. In other cases, we may require additional information or let you know that we need more time to respond. If you have any questions (or comments) concerning this Privacy Policy, you are welcome to send us an email at: privacy@nuvocares.com and we will make an effort to reply within a reasonable timeframe.
COOKIE POLICY
We use certain monitoring and tracking technologies, including ones offered by third party service providers to collect and process the personal information we specified above. These technologies are used to maintain, provide and improve the Invu System on an ongoing basis, in order to provide a better experience to our Users. For example, these technologies enable us to: (i) more easily authenticate a user,(ii) keep track of the frequency of usage of the Invu System by a user and apply her preferences, (iii) better secure the Invu System by detecting abnormal behaviors, (iv) identify technical issues and improve the overall performance of the Invu System, and (iv) monitor analytics relating to use of the Invu System.
Based on the foregoing, we’ve adopted this policy ("Cookie Policy")to explain how we use cookies and your related choices and options. In this policy we use the term "cookies" to refer to any applicable tracking technologies described herein.
1. WHAT ARE COOKIES
- Cookies are a small text file that is stored on your device to help websites and mobile apps remember things about you. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire. To learn more about cookies, visit http://www.allaboutcookies.org/
- Pixel Tags (also known as web beacons or clear GIFs) are transparent images, iFrames, orJavaScript placed on a website or in marketing emails that are used to understand how you interact with such websites or emails.
- Social Media Features, such as theFacebook "like" button, may collect your IP address and which page you are visiting on a website, and may set a cookie to enable the feature to function properly. Your interactions with these features are governed by the privacy policy of the company providing the relevant Social Media Features.
- Single Sign-on allows you to log into certain websites or mobile applications using sign-in services provided by third parties, such as Facebook or Google. Theses ervices will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our sign-up form.
2. HOW WE USE COOKIES
The cookies we use can be classified in one of the following categories:
Strictly Necessary cookies - We use these cookies to enable you to use the Invu System features. Without these necessary cookies, services and functions within the Invu System will not be possible and the system will not perform as it should.
Security cookies - We use these cookies to help identity and prevent security risks.
Authentication cookies - We use these cookies to help us show you the right information and settings when you are logged-in to the Invu System.
Performance and Analytics cookies - We use these cookies to collect information about a users’ use of the Invu System to help improve the way the system operates.
Functionality and Preference cookies - We use these cookies to remember the choices you make such as which language you prefer and to provide you with personalized features.
3. CHANGES TO THIS COOKIE POLICY
We may update this Cookie Policy from time to time. We encourage you to periodically review this Cookie Policy to stay informed about our use of cookies, the information we collect via cookies, and any updates in relation thereto. If we make any changes to this Cookie Policy that significantly impact the way we use cookies, we will endeavor to provide you with notice in advance of such change by highlighting the change on our Website. Your continued use of the Invu System constitutes your agreement to this Cookie Policy and any updates.
4. CONTACT US
If you have any questions about our use of cookies, please contact us at privacy@nuvocares.com.
Last Updated: February 2024