Empatho is a mobile app that helps organizations improve the health and wellness of every employee. Powered by our proprietary PsychAI™ Artificial Intelligence, Empatho provides data-driven insights and personalized guidance
to improve total wellbeing.
I. WHAT INFORMATION MAY THE APPLICATION COLLECT FROM YOU?
A. Personal Information
We request that you register with us to use the Application. Registration with us is optional; however, you may not be able to use many of the features offered by the Application unless you register.
We will ask you to fill out demographic, personality, and overall well-being information when you begin using the application. You will also be required to provide COVID-19 “Return to Work” screening information, such as your vaccination status. We may periodically ask you to answer questions about yourself (e.g., your sleep, mood, and your energy and activity level) and your current overall wellbeing (e.g., your happiness levels and coping mechanisms) to track changes and provide helpful feedback.
We will electronically process your data and separate your account information (email) from your data (your responses to surveys and the measurements from the phone itself when you perform activities). We will combine your coded data (without your name or other identifying information) with those of other users. The combined data will be encrypted and transferred electronically to secure servers at Google’s Firebase platform for storage, and will be accessible only by Empatho Corp.
B. Automatically Collected Non-Personal Information.
The Application may collect certain non-personal information automatically that does not, on its own, permit direct association with any specific individual. The Application will collect Motion and Fitness data, Health data, and your location data from your mobile device and/or wearable device. Then periodically we will ask you to answer questions via the Application from your phone. These survey questions may be about your health, exercise, diet, sleep, medicines, etc. or about how you are feeling in general. Your data will include your responses to question prompts and the measurements from the phone itself.
C. Location Information.
We may request and collect your geographic location from your mobile device or your IP address to determine environmental information such as weather, air quality, and nearby greenery.
II. HOW IS YOUR PERSONAL INFORMATION USED?
User personal information is collected to provide a service or function that is directly relevant to the use of the Application. Data collected through the application is anonymized and aggregated to provide business-level insights to the user’s employer. Individual users (employees) are not identifiable through this process and individual employee personal information or wellbeing data is not available to the employer. Business insights are provided on a company-wide basis only in order to protect the privacy and confidentiality of employees.
The research team will also analyze the combined data to continue to develop the Empatho platform. Your data, without your name, will be added to the data of other users and may be analyzed by the research and development team.
III. IS YOUR PERSONAL INFORMATION SHARED WITH ANY THIRD PARTIES OUTSIDE THE COMPANY?
We may share your personal information outside the Company as required by law, order of governmental authority, or court order to be disclosed; when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request. We may also share your personal information if permitted under Empatho Corp policy, authorized by an approved Empatho Corp contract, for good cause by the Officers of the Empatho Corp. Empatho and its subcontractors may be able to review anonymized personal information as well as aggregated employer-level data to continue to develop and improve the Empatho platform. Empatho’s subcontractors are subject to and compliant with Empatho privacy policies and all relevant privacy regulations.
IV. HOW IS YOUR PERSONAL INFORMATION PROTECTED?
We are committed to protect your information and keep your identity as confidential as possible, however total confidentiality cannot be guaranteed. Except as required by law, you will not be identified by name or by any other direct personal identifier. The data collected through the app will be encrypted on the smartphone, transferred electronically and stored securely using cloud services on the HIPAA-compliant platform. Empatho is powered by a proven platform that actively builds in, monitors, maintains and guarantees cloud data security and privacy compliance specifically for healthcare in Canada. The platform is SOC 2 certified, with policies mapped directly to ISO 27001. Your contact information, including your name and e-mail address, will be stored separately from the passive data. We will use a random code number instead of your name on all your data. Information about the code will be kept in a secure system. We will not access your personal contacts, other applications, text or email message content, or websites visited. We will never sell, rent or lease your contact information. We follow generally accepted industry standards and requirements, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Personal Health Information Protection Act (PHIPA) to protect the personal information submitted to us. No method of transmission, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security.
This information should not be construed in any way as giving business, legal, or other advice, or warranting as fail proof, the security of information provided via the Application.
V. OPT-OUT INFORMATION
Although you can discontinue your use of the Application at any time, you cannot withdraw the coded data that has already been distributed. If you stop using the Application, we will stop collecting new data but the coded data that you have already provided will not be able to be destroyed or deleted.
VI. HOW LONG IS YOUR PERSONAL INFORMATION STORED?
We will retain user data and Personal Identifiable Information (PII) such as your name, email, and exact coordinates for as long as you use the Application and for as long as the information serves a specific purpose thereafter, in accordance with PIPEDA, HIPAA, and GDPR requirements. Please note that some or all of the user personal information may be required for the Application to function properly, and we may be required to retain certain information by law. If you have further questions about how your personal information is collected, stored, or used, please contact the Empatho development team for further assistance.
Contact information for the Empatho privacy team is as follows:
222 Bay Street,
PO Box 37, Suite 2600
Toronto, ON M5K 1B7
The Company is committed to complying fully with the children’s online privacy protection measures as outlined by the Office of the Privacy Commissioner of Canada (OPC). Accordingly, if a user of the Application is under the age of eighteen, such user is not authorized to provide the Company with personal information, and the Company will not use any such information in its database or other data collection activities. The Company appreciates cooperation with these federally mandated guidelines. This application is only intended for use by individuals over the age of eighteen. Users under the age of eighteen and their parents or guardians are cautioned that the collection of personal information volunteered by unauthorized children online or by e-mail will be treated the same as information given by an adult until the Company becomes aware that the user is under the age of eighteen and such information may be subject to public access.
VIII. INTERACTIVE SERVICES/SOCIAL MEDIA WEBSITES
If you post a Comment, Activity Post or otherwise provide Personal Information by and through the Interactive Services, the Site and/or any applicable Social Media Website, you should be aware that any Personal Information that you submit using such forums can be read, collected or used by other users of these forums (depending on your privacy settings, in the case of Social Media Websites), and could be used to send you unsolicited messages or otherwise contact you without your consent or desire. We are not responsible for the Personal Information that you choose to submit in these forums. If you mistakenly post Personal Information in our Social Media forums and would like it removed, you can send us an email to email@example.com to request that we remove it. In some cases, we may not be able to remove such Personal Information.
The Social Media Websites operate independently from Empatho Corp, and we are not responsible for such Social Media Websites’ interfaces or privacy or security practices. We encourage you to review the privacy policies and settings on the Social Media Websites with which you interact to help you understand those Social Media Websites’ privacy practices. If you have questions about the security and privacy settings of any Social Media Websites that you use, please refer to their applicable privacy notices or policies. Further, by submitting Comments, Activity Posts and/or other material via the Interactive Services, the Site, the Services and/or Social Media Websites, you:
represent and warrant that Empatho’s use of your submission does not and will not breach any agreement, violate any law, violate any Social Media Website’s terms of service or infringe upon any third party’s rights;
agree that Empatho is free to use in any manner all or part of the Comments, Activity Posts and/or other material on an unrestricted basis without the obligation to notify, identify or compensate you or anyone else; and
grant Empatho all necessary rights, including a waiver of all copyright, trademark, privacy and moral rights, to use all Comments, Activity Posts and/or other material, in whole or in part, or as a derivative work, without any duty by Empatho to anyone whatsoever.
IX. CHANGES TO THIS PRIVACY STATEMENT
We may amend this Privacy Notice from time to time. If we change this Privacy Notice we will post the changes on empatho.com. Your continued use of our Application after any such changes will constitute your acceptance of the updated Privacy Notice. If you do not wish to accept the revised Privacy Notice, you must not use or access (or continue to use or access) our Application. Please regularly check our website to determine if the Privacy Notice has been updated to review those changes before deciding whether or not to access (or continue to access) our Application.
X. USER ACCESS TO INFORMATION AND CONTACT INFORMATION
To review and update your personal information to ensure it is accurate or to receive a copy of your data, contact us at firstname.lastname@example.org.
XI. DISCLAIMER OF WARRANTIES.
YOU EXPRESSLY AGREE THAT USE OF THE APPLICATION AND ANY CONTENT (SUCH AS TEXT, DATA, INFORMATION, AUDIO, VIDEOS, GRAPHICS, OR PHOTOGRAPHS) MADE AVAILABLE THROUGH THIS APPLICATION (COLLECTIVELY, “MATERIALS”), IS AT YOUR SOLE RISK. THE APPLICATION AND MATERIALS, ARE PROVIDED ON AN “AS IS,” “AS AVAILABLE,” AND “WITH ALL FAULTS” BASIS. THE COMPANY DISCLAIMS ALL EXPRESS AND IMPLIED CONDITIONS, REPRESENTATIONS, AND WARRANTIES OF ANY KIND, INCLUDING BUT NOT LIMITED TO ANY IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. THE COMPANY MAKES NO WARRANTY THAT THE SERVICE WILL MEET YOUR REQUIREMENTS OR THAT THE APPLICATION OR THE MATERIALS, WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR FREE; NOR DOES THE COMPANY MAKE ANY WARRANTY FOR ANY PURPOSE OF THE APPLICATION OR MATERIALS OR RESULTS THAT MAY BE OBTAINED THROUGH USE OF THE APPLICATION OR AS TO THE ACCURACY, SAFETY, RELIABILITY OR USEFULNESS OF ANY INFORMATION OBTAINED THROUGH THE APPLICATION. THE COMPANY DISCLAIMS ANY WARRANTY THAT THE APPLICATION OR THE MATERIALS, ARE FREE OF VIRUSES, WORMS, TROJAN HORSES, OR OTHER CODE THAT MANIFESTS CONTAMINATING OR DESTRUCTIVE PROPERTIES.
XII. LIMITATION OF LIABILITY.
THE COMPANY, ITS TRUSTEES, DIRECTORS, OFFICERS, STAFF, EMPLOYEES, CONSULTANTS AND AGENTS ASSUME NO LIABILITY IN RESPECT OF ANY INFRINGEMENT OF ANY COPYRIGHT, TRADEMARK, PATENT OR OTHER RIGHT OF THIRD PARTIES ARISING IN CONNECTION WITH THE APPLICATION AND MATERIALS AND ARE NOT LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, SPECIAL, INCIDENTAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES (INCLUDING, WITHOUT LIMITATION, ANY DAMAGES CAUSED BY USE AND IMPLEMENTATION OF MATERIALS, LOSS OF BUSINESS, REVENUE, PROFITS, GOODWILL, USE, DATA OR OTHER ECONOMIC ADVANTAGE) ARISING OUT OF OR IN CONNECTION WITH THE APPLICATION OR MATERIALS, EVEN IF THE COMPANY, ITS TRUSTEES, DIRECTORS, OFFICERS, STAFF, EMPLOYEES, CONSULTANTS AND/OR AGENTS HAVE PREVIOUSLY BEEN ADVISED OF, OR REASONABLY COULD HAVE FORESEEN, THE POSSIBILITY OF SUCH DAMAGES, HOWEVER THEY ARISE, WHETHER IN BREACH OF CONTRACT OR IN TORT (INCLUDING NEGLIGENCE OR GROSS NEGLIGENCE). YOU HAVE SOLE RESPONSIBILITY FOR ADEQUATE PROTECTION AND BACKUP OF DATA AND/OR EQUIPMENT USED IN CONNECTION WITH THE APPLICATION.
XIII. GOVERNING LAW.
Construction of the Privacy Notice, including without limitation, disclaimers above and resolution of disputes thereof are governed by the laws of the Province of Ontario and the Government of Canada. These laws shall apply to all uses of this Application and Materials. By use of this Application and Materials, the user agrees that use shall conform to all applicable laws and regulations and the user shall not violate the rights of any third parties.
XIV. DEFINITIONS AND LEGAL REFERENCES.
Personal Data (or “Data”):
Any information that directly, indirectly, or in connection with other information—including a personal identification number—allows for the identification or identifiability of a natural person.
Personal Identifiable Information (PII):
Information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother’s maiden name, etc.
Information collected automatically through this application (or obtained by services employed in this application)can include: the IP addresses or domain names of the computers utilized, the Uniform Resource Identifier (URI) addresses, the time of the request, the method used to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the users’ browser and operating system, the various time details per visit (e.g., the time spent on each page within the application), and the information on the path followed within the application with particular reference to the sequence of pages visited, and other parameters about the device operating system or the users’ IT environment.
The individual using this application who, unless otherwise specified, coincides with the data subject.
The natural person to whom the personal data refers.
The natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller, as described in this privacy notice.
This refers to any additional third party who processes personal data on behalf of the data processor in fulfilling contractual obligations and services.
The person, public authority, agency, or other body that determines the purposes and means of processing personal data, including the security measures concerning the operation and use of this application.
The information technology system that collects and processes the personal data of the user.
The service provided by the Empatho platform or Empatho team.
This privacy notice has been prepared based on provisions of multiple legislations, including Art. 13/14 of Regulation (EU) 2016/679 (General Data Protection Regulation).
This privacy notice relates to the Empatho website, application, and supporting services unless otherwise stated within this document.