Privacy Policy

Please read these privacy policies carefully before using our services.

Last Updated: September 7, 2026

Healium Intelliscan ("Healium Intelliscan," "Healium," "we," "our," or "us") respects your privacy and is committed to protecting the confidentiality, integrity, and security of personal information and health information.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with our website, software, applications, AI-powered ultrasound technology, tele-guidance services, and related products and services (collectively, the "Services").

Our Services are primarily provided to healthcare providers, hospitals, clinics, medical professionals, and other healthcare organizations.

Because we operate and provide Services internationally, different privacy and data protection laws may apply depending on the individual, organization, location, and circumstances involved. These laws may include the U.S. Health Insurance Portability and Accountability Act ("HIPAA"), the European Union General Data Protection Regulation ("GDPR"), Singapore's Personal Data Protection Act ("PDPA"), and other applicable privacy and data protection laws.

This Privacy Policy should be read together with our applicable Terms and Conditions, Business Associate Agreements ("BAAs"), Data Processing Agreements ("DPAs"), and other agreements governing our Services.

1. Our Role and Responsibilities

Healium Intelliscan may act in different privacy roles depending on the nature of the information and the Services being provided.

Healthcare Information

When we process Protected Health Information ("PHI") on behalf of a healthcare provider that is a HIPAA Covered Entity, we generally act as a Business Associate under HIPAA.

Our processing of PHI is governed by applicable HIPAA requirements, our Business Associate Agreements, customer instructions, and other applicable contractual and legal requirements.

The healthcare provider generally determines the purposes for which patient information is collected and processed.

Personal Information

For information such as website visitor information, business contact information, account information, employment information, and information that we process directly for our own business purposes, Healium Intelliscan may act as a controller, business, or other responsible organization under applicable privacy laws.

Where we process personal information solely on behalf of a customer, we may act as a processor, service provider, or equivalent role under applicable law.

Our role depends on the nature of the information, the Services provided, our contractual relationship, and applicable law.

2. Information We Collect or Process

Depending on how you interact with our Services, we may collect or process the following categories of information.

2.1 Protected Health Information

When healthcare providers use our Services, we may process PHI on their behalf.

This may include:

  • Patient names;
  • Dates of birth;
  • Medical record numbers;
  • Patient identification information;
  • Diagnostic images, including ultrasound images;
  • Clinical findings;
  • Medical history;
  • Treatment information;
  • Clinical notes;
  • Diagnostic information;
  • Information concerning physical or mental health;
  • Information concerning healthcare services provided to a patient; and
  • Other information that identifies or relates to a patient.

The specific information processed depends on the Services and configuration used by the healthcare provider.

2.2 Account and Business Information

When healthcare providers, customers, users, or their representatives create accounts or interact with us, we may collect:

  • Name;
  • Professional title;
  • Organization;
  • Email address;
  • Telephone number;
  • Business address;
  • Account information;
  • Authentication information;
  • Customer support information;
  • Communications with us; and
  • Other information necessary to provide and manage our Services.

2.3 Technical and Usage Information

When you access our website or Services, we may automatically collect technical information, including:

  • IP address;
  • Device type;
  • Browser type;
  • Operating system;
  • Application version;
  • Device identifiers;
  • Log information;
  • Access dates and times;
  • Service usage information;
  • Performance information;
  • Error information;
  • Network information; and
  • Security-related information.

We use this information to operate, secure, maintain, monitor, and improve our Services.

Where appropriate, information may be aggregated, anonymized, or de-identified.

2.4 Information You Provide to Us

We may collect information that you voluntarily provide when you:

  • Contact us;
  • Submit a form;
  • Request a demonstration;
  • Request information about our Services;
  • Communicate with our support team;
  • Communicate with us by email or other channels;
  • Participate in surveys or other activities; or
  • Otherwise interact with us.

This may include your name, email address, organization, job title, telephone number, message contents, and other information you choose to provide.

2.5 Employment and Recruitment Information

If you apply for employment or work opportunities with Healium Intelliscan, we may process information such as:

  • Name;
  • Contact information;
  • Resume or CV;
  • Employment history;
  • Education;
  • Professional qualifications;
  • References;
  • Interview information; and
  • Other information you voluntarily provide during the recruitment process.

We use this information for recruitment, evaluation, hiring, onboarding, and related employment purposes.

3. How We Use Information

We use and process information for purposes permitted by applicable law and our contractual obligations.

Providing and Maintaining Our Services

We may use information to:

  • Provide our AI-powered ultrasound technology;
  • Provide tele-guidance and healthcare technology services;
  • Process ultrasound information;
  • Generate reports and diagnostic-support outputs;
  • Facilitate communication between healthcare professionals;
  • Manage user accounts;
  • Provide customer and technical support;
  • Maintain and operate our systems; and
  • Ensure the availability and functionality of our Services.

Service Improvement

We may use information to:

  • Analyze service usage;
  • Troubleshoot technical problems;
  • Improve system performance;
  • Improve usability;
  • Develop new features;
  • Improve AI algorithms and models; and
  • Improve the reliability and effectiveness of our Services.

Where appropriate and legally permitted, we use de-identified, anonymized, or aggregated information for these purposes.

Security

We may process information to:

  • Detect and prevent unauthorized access;
  • Detect fraud and abuse;
  • Monitor system security;
  • Investigate security incidents;
  • Protect our infrastructure;
  • Maintain system integrity; and
  • Prevent misuse of our Services.

Legal and Regulatory Compliance

We may process information to:

  • Comply with applicable laws and regulations;
  • Respond to lawful requests from authorities;
  • Meet regulatory requirements;
  • Enforce our agreements;
  • Protect our legal rights;
  • Resolve disputes; and
  • Fulfill contractual obligations.

Research and Development

Where permitted by applicable law and contractual agreements, we may use appropriately de-identified, anonymized, aggregated, or otherwise lawfully processed information for research, development, testing, validation, and improvement of healthcare and AI technologies.

Where authorization or consent is required, appropriate authorization or consent will be obtained.

4. Legal Bases for Processing Under GDPR

Where the GDPR applies, we process personal data only where an appropriate legal basis exists.

Depending on the circumstances, our legal bases may include:

Performance of a Contract

We may process personal data where processing is necessary to enter into or perform a contract with you or your organization.

Legal Obligation

We may process personal data where necessary to comply with a legal or regulatory obligation.

Legitimate Interests

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of the individual.

These interests may include:

  • Securing our Services;
  • Preventing fraud and abuse;
  • Operating and maintaining our systems;
  • Improving our Services;
  • Managing business relationships; and
  • Protecting our legal rights.

Consent

Where required by applicable law, we may process personal data based on your consent.

You may withdraw consent at any time where permitted by law. Withdrawal of consent does not affect the lawfulness of processing that occurred before consent was withdrawn.

Vital Interests

Where legally applicable, we may process personal data where necessary to protect the vital interests of an individual or another person.

The applicable legal basis depends on the specific processing activity and circumstances.

5. HIPAA and Protected Health Information

Where applicable, Healium Intelliscan processes PHI in accordance with HIPAA and our contractual obligations as a Business Associate.

We do not use or disclose PHI except as permitted or required by applicable law, our Business Associate Agreements, customer instructions, or other applicable agreements.

We do not sell PHI.

Where required, we will assist our healthcare provider customers in meeting their obligations regarding PHI, including applicable patient rights requests, security requirements, and breach-related obligations.

6. Disclosure of Information

We may disclose information in the following circumstances.

Healthcare Providers and Customers

We may disclose or provide information to the healthcare provider, organization, or other customer that authorized us to process the information.

Service Providers and Subcontractors

We may engage third-party service providers and subcontractors to support our Services.

These providers may provide services such as:

  • Cloud hosting;
  • Data storage;
  • Infrastructure;
  • Security;
  • Customer support;
  • Analytics;
  • Communications;
  • Software operations; and
  • Other business and technical services.

We require applicable service providers to implement appropriate safeguards and process information only as permitted by applicable agreements and law.

Where PHI is involved, applicable HIPAA and Business Associate requirements will apply.

Legal Requirements

We may disclose information when required or permitted by applicable law, including in response to:

  • Court orders;
  • Subpoenas;
  • Legal processes;
  • Government requests;
  • Regulatory requests; or
  • Law enforcement requirements.

Protection of Rights and Safety

We may disclose information where reasonably necessary to:

  • Protect our rights or property;
  • Protect users;
  • Investigate fraud or abuse;
  • Prevent security threats;
  • Protect the safety of individuals; or
  • Address emergencies.

7. Data Security

Healium Intelliscan maintains administrative, technical, and physical safeguards designed to protect personal information and PHI against unauthorized access, use, disclosure, alteration, loss, or destruction.

Depending on the information and Services involved, these measures may include:

Encryption

Information is encrypted in transit and, where applicable, at rest using appropriate security technologies.

Access Controls

Access to sensitive information is restricted to authorized personnel based on business need and the principle of least privilege.

Authentication

We use appropriate authentication and account-security controls to protect access to our systems.

Monitoring and Logging

Our systems may be monitored and logged to identify:

  • Unauthorized access;
  • Suspicious activity;
  • Security incidents;
  • System failures; and
  • Other security risks.

Employee Training

Personnel who have access to sensitive information receive appropriate privacy, security, confidentiality, and compliance training.

Physical Security

Infrastructure and facilities supporting our Services are protected using appropriate physical and environmental security measures.

Although we implement reasonable safeguards, no method of transmitting or storing information is completely secure. We therefore cannot guarantee absolute security.

8. Data Retention

We retain information only for as long as reasonably necessary to:

  • Provide our Services;
  • Fulfill contractual obligations;
  • Comply with legal and regulatory requirements;
  • Maintain appropriate business and financial records;
  • Resolve disputes;
  • Enforce agreements;
  • Maintain security; and
  • Meet audit and compliance requirements.

Retention periods depend on factors including:

  • The type and sensitivity of information;
  • The purpose for which the information was collected;
  • Our relationship with the customer;
  • Applicable healthcare requirements;
  • Legal and regulatory obligations; and
  • The terms of applicable agreements and BAAs.

When information is no longer required, we will delete, anonymize, or otherwise securely dispose of it in accordance with applicable law and contractual requirements.

9. International Data Transfers

Healium Intelliscan operates in an international environment. Personal information may therefore be accessed, stored, or processed in countries other than the country in which the information was originally collected.

Information may be processed by:

  • Healium Intelliscan personnel;
  • Healthcare customers;
  • Contractors;
  • Service providers;
  • Subcontractors; or
  • Infrastructure providers

located in different countries.

Where applicable law restricts international transfers, we implement appropriate legal safeguards.

Where the GDPR applies, such safeguards may include:

  • An adequacy decision;
  • Standard Contractual Clauses;
  • Appropriate contractual safeguards;
  • Transfer risk assessments where required; and
  • Other legally recognized transfer mechanisms.

Where Singapore's PDPA applies, we take appropriate steps to ensure that personal data transferred outside Singapore receives a level of protection comparable to the protection required under applicable Singapore law.

10. GDPR Data Protection Rights

Where the GDPR applies, individuals may have certain rights regarding their personal data.

These rights may include:

Right of Access

You may request access to personal data we hold about you.

Right to Rectification

You may request correction of inaccurate or incomplete personal data.

Right to Erasure

You may request deletion of your personal data in circumstances where applicable law provides this right.

Right to Restriction of Processing

You may request restriction of processing in certain circumstances.

Right to Data Portability

Where applicable, you may request your personal data in a structured, commonly used, and machine-readable format.

Right to Object

You may have the right to object to certain processing activities, including processing based on legitimate interests.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time, subject to applicable law.

Rights Relating to Automated Decision-Making

Where applicable, you may have rights relating to decisions based solely on automated processing, including profiling.

Because Healium Intelliscan may process healthcare information on behalf of healthcare providers, requests relating to patient information may need to be directed to the relevant healthcare provider.

11. Singapore Personal Data Protection Act

Where Singapore's Personal Data Protection Act ("PDPA") applies, Healium Intelliscan handles personal data in accordance with applicable PDPA requirements.

Our privacy practices include the following:

Collection, Use, and Disclosure

We collect, use, and disclose personal data only for purposes that are appropriate and permitted under applicable law.

Notification and Consent

Where required, we provide appropriate notice regarding the purposes for which personal data is collected, used, or disclosed and obtain consent where required.

Purpose Limitation

We seek to collect, use, and disclose personal data only for appropriate purposes and in accordance with applicable legal requirements.

Protection

We implement reasonable security arrangements to protect personal data against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks.

Accuracy

Where personal data is likely to be used to make a decision affecting an individual or disclosed to another organization, we take reasonable steps to ensure that the information is sufficiently accurate and complete for its intended purpose.

Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or as otherwise required or permitted by law.

Access and Correction

Subject to applicable legal exceptions, individuals may request access to or correction of their personal data held by us.

International Transfers

Where personal data is transferred outside Singapore, we take appropriate steps to ensure that the transferred personal data is protected to a standard comparable to the protection required under applicable Singapore law.

12. Privacy Requests

If you wish to exercise a privacy right, request access to your personal information, request correction or deletion, or raise a concern regarding our privacy practices, you may contact us using the contact information provided below.

We may need to verify your identity before processing a request.

We will respond to requests within the timeframes required by applicable law.

If you are a patient whose information is processed through a healthcare provider using our Services, you may need to submit your request directly to that healthcare provider.

Where appropriate and legally required, we will cooperate with our healthcare provider customers to help them respond to privacy and patient-rights requests.

13. Cookies and Similar Technologies

Our website and Services may use cookies and similar technologies to:

  • Operate and secure our website;
  • Remember preferences;
  • Understand website usage;
  • Analyze website and service performance;
  • Improve user experience;
  • Maintain security; and
  • Support certain communications and marketing activities.

Some cookies may be provided by third-party service providers.

Where required by applicable law, we will obtain consent before placing or using non-essential cookies and similar technologies.

You may also be able to manage cookies through your browser settings or available cookie-management tools.

Additional information about our use of cookies may be provided in our Cookie Policy.

14. Children's Privacy

Our Services are primarily intended for healthcare providers, healthcare organizations, medical professionals, and business users.

We do not knowingly collect personal information directly from children through our website for purposes unrelated to healthcare services.

Where information concerning a child is processed as part of healthcare services, such information may be processed on behalf of the relevant healthcare provider in accordance with applicable healthcare and privacy laws.

15. Third-Party Websites and Services

Our website or Services may contain links to third-party websites, applications, or services.

We are not responsible for the privacy practices, security, or content of third-party services that we do not control.

We encourage you to review the privacy policies of third-party websites and services before providing them with personal information.

16. Data Breach and Security Incidents

Healium Intelliscan maintains procedures designed to detect, investigate, respond to, and remediate security incidents.

Where applicable law requires notification of a personal-data breach or security incident, we will provide notifications to the appropriate parties within the timeframes required by applicable law.

For PHI, we will comply with applicable HIPAA breach-notification requirements and our contractual obligations under applicable Business Associate Agreements.

17. Your Privacy Responsibilities

If you use our Services on behalf of a healthcare provider or other organization, you are responsible for using the Services in accordance with your organization's policies, applicable agreements, and applicable laws.

Users should not provide information to Healium Intelliscan through channels that are not intended for the transmission of sensitive or health information.

Healthcare providers remain responsible for obtaining any required patient notices, authorizations, consents, or other permissions necessary for their use of our Services, except where otherwise agreed in writing or required by applicable law.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our Services;
  • Changes to our business operations;
  • Changes in applicable laws;
  • Regulatory developments;
  • Changes to our privacy practices; or
  • Improvements to our security and privacy practices.

When we make material changes, we may provide appropriate notice through our website, Services, or other communication channels.

The "Last Updated" date at the beginning of this Privacy Policy indicates when this Privacy Policy was most recently revised.

19. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or wish to exercise a privacy right, please contact us:

Healium Intelliscan

Email: info@healiumintelliscan.com

Address: 26 Broadway, Suite 934-G68, New York, NY 10004, USA

Privacy Officer / Data Protection Officer: +1 (302) 310-4257

Where applicable, individuals located in the European Economic Area may also have the right to lodge a complaint with their relevant data protection supervisory authority.

20. Governing Privacy Requirements

Nothing in this Privacy Policy limits any rights or protections that cannot lawfully be limited under applicable privacy, healthcare, or data-protection laws.

Where there is a conflict between this Privacy Policy and a legally binding agreement or applicable law, the applicable agreement or law will govern to the extent required.

Learn more about Our Solution