Privacy Policy

1. Introduction

Welcome to HeartInCare ("we," "us," or "our"). This Privacy Policy outlines our commitment to protecting your personal data and respecting your privacy rights. It details our practices regarding the collection, use, storage, and sharing of your personal information when you access or use our platform, including our website (https://www.heartincare.com), Android application, and iOS application (collectively, the "Services"). By accessing or using our Services, you acknowledge and agree to the terms of this Privacy Policy.

2. Company Information

HeartInCare is operated by İNVİCTUS TURİZM KONGRE VE ORGANİZASYON HİZMETLERİ LİMİTED ŞİRKETİ, a limited liability company registered in Turkey, with its registered office located at Halaskargazi Cad. Teyyareci Cemal Sk. No:3 D:1 34360 Şişli/İstanbul.

For detailed information on our data processing activities as a data controller, please refer to our Policy on Processing of Personal Data and Disclosure Text.

3. Information We Collect

Personal Information

We collect personal data including but not limited to names, contact details, and health-related information necessary to provide our health monitoring services. This data is collected strictly in accordance with the principle of data minimization, ensuring that only data essential for the provision of our Services is processed.

Health Information

Subject to your explicit consent, we may collect specific health metrics including heart rate, blood pressure, electrocardiogram (ECG) measurements, step count, sleep patterns, stress levels, and blood oxygen saturation (SpO2) levels.

Usage Information

We collect technical data regarding your interactions with our website and Services to optimize user experience and system performance. This includes operational logs such as user authorization records and service cancellation logs.

Non-Personal Information

We may process anonymized, aggregated data for analytical purposes to improve our Services.

4. Data Sources

Direct Input

Information manually provided by you directly within the HeartInCare application.

Health Service Kit Data

With your explicit consent, we may retrieve health data from third-party health frameworks (e.g., Apple HealthKit, Google Health Connect). This includes metrics such as heart rate, blood pressure, ECG measurements, step count, sleep patterns, stress levels, and SpO2 levels. Such data is obtained directly via integrated APIs within the HeartInCare application.

5. Purposes of Processing

Health Monitoring

Your health-related data is processed to provide real-time monitoring services and generate personalized health insights. This processing is necessary to enable the core functionality of HeartInCare. Data obtained from HealthKit is utilized solely for reference and informational purposes and is not intended for use in medical diagnosis or treatment.

Service Improvement

Collected data is utilized to enhance Service quality, address user requirements, and optimize the technical functionality of the HeartInCare platform.

Analytics

We utilize non-sensitive, anonymized data to analyze usage patterns and improve application performance and features.

6. Data Security

Security Measures

HeartInCare implements robust, industry-standard technical and administrative security measures to protect your data against unauthorized access, disclosure, alteration, or destruction. Our security protocols cover the entire data lifecycle, from transmission to storage, ensuring the confidentiality, integrity, and availability of your information.

Encryption

All sensitive personal data, including health information, is stored in encrypted format to ensure maximum security.

7. Data Storage and Retention

Storage Location

Data collected by HeartInCare is securely stored either locally on your device or on our cloud servers, depending on the nature of the data. Sensitive health-related information is encrypted and stored anonymously to further protect your privacy. Our servers are located in Germany, adhering to strict data protection standards.

Data Retention Period

Personal data is retained only for the duration necessary to fulfill the purposes outlined in this Privacy Policy. Upon the expiration of the retention period, or upon your request, data will be securely deleted or anonymized in accordance with applicable laws.

8. Cross-Border Data Transfer

In the event of any cross-border data transfer, HeartInCare ensures full compliance with applicable data protection laws. Users will be informed prior to any such transfer, and appropriate safeguards will be implemented to protect personal data during international transit.

9. Sharing of Information

Third-Party Services

We may share non-personal and non-health-related data with trusted third-party service providers solely for the purpose of facilitating operational functions such as website hosting, analytics, and customer support.

Health Data Sharing

Your sensitive health data is treated with the strictest confidentiality. Access is restricted to healthcare professionals explicitly authorized by you for the purpose of providing personalized care. HeartInCare ensures that your health information is shared strictly within the scope of your authorization. For further details, please review the User Explicit Consent Text.

10. User Rights

Access and Export

You have the right to request a copy of your personal data. An export option is available directly within the application.

Correction and Deletion

You have the right to request the correction of inaccurate data or the deletion of your personal information. You may clear your data via the in-app settings. Additionally, you may exercise your rights by submitting our KVKK Application Form.

Withdraw Consent (HealthKit)

You may revoke your authorization for the application to read or write data to HealthKit at any time via your device settings. Upon revocation, the application will cease accessing HealthKit data. Historical data may be retained or deleted based on your preference.

11. Consent

HealthKit Data Access

We require your explicit consent prior to accessing reading or writing data to HealthKit or similar third-party health services.

Third-Party Disclosure

We obtain your explicit consent before disclosing any personal data to third parties, except as strictly detailed in this Privacy Policy or required by law.

12. Children’s Privacy

Our Services are not intended for individuals under the age of 16. We do not knowingly collect or solicit personal data from children under 16.

13. Updates to Privacy Policy

We reserve the right to update this Privacy Policy periodically. Users will be notified of any material changes to this policy.

14. Contact Us

If you have any questions or concerns regarding this Privacy Policy, please contact us via email at [email protected].

By using HeartInCare, you acknowledge that you have read and understood the terms of this Privacy Policy.

* This document is for informational purposes.