Last updated: September 24 2020
Effective date and version: September 24 2020, version 4.0
We at Memaxi ehf ("us", "we", or "our") are committed to providing quality service to you. We appreciate that you are trusting us with information that is personal and important to you and we do our best to keep your information safe and only use it your best interest.
Memaxi is a care and communications solution and offered as a subscription-based solution (“Service”) for beneficiaries of care and their informal (family) and professional carers. It is used to help manage person-centered care plans, increase communication with the beneficiary with the use of video calls and photos and plan and record care and assistance provided.
Most of the information you and your carers provide to us through Memaxi is used to help you go about your daily life and keeping this information private is of utmost importance.
|Beneficiary (of care)
||The person requiring care and assistance. The person using Memaxi Display
||A registered Memaxi user who has been authorised by the Display Profile Beneficiary to help manage the Display Profile, either a professional carer or informal/family carer
||Cookies are small pieces of data stored on your device (computer or mobile device)
||Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the way any personal information are, or are to be, processed
||Data Subject is any living individual who is using our Service and is the subject of Personal Data
|Data Subject (or User)
||Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession)
||A registered Memaxi user who has been authorised by the Display Profile Beneficiary to help manage the Display Profile, either a professional carer or informal/family carer
||A Profile is the collection of information relating to a Beneficiary. It may hold calendar events, notes, photos, guestbook entries and other information relating to the daily life of the person the Display Profile is intended for
||A collection of beneficiary profiles and carers. Available only in Memaxi PRO
||Usage Data is data collected automatically either generated by using the Service or from the Service infrastructure itself (for example, the duration of a page visit)
||Service means our devices, applications, software, websites, APIs, products and services, including but not limited to the website www.memaxi.com and its sub-sites, the Memaxi Display, Memaxi Connect and Memaxi Lock mobile applications and the Memaxi Web application operated by Memaxi ehf
||Mobile application, usually run on smartphones, with access to beneficiary information
||Mobile application, usually run on a tablet computer, with an overview of the beneficiary’s day
||Web application of Memaxi
||For private use for a beneficiary and their informal carers. For Memaxi HOME, Memaxi ehf acts both as a Data Controller and a Data Processor
||For professional use of care providers who service multiple beneficiaries. Such care providers act as Data Controllers under the GDPR and Memaxi acts as a Data Processor
INFORMATION COLLECTION AND USE
When you user our Service we collect several types of information for various purposes to provide and improve our Service to you.
Information you provide us with:
Carer / user account information
Some personally identifiable information that can be used to contact or identify you (“Personal Data”) is required to create an account on our Service, such as your name, email address and password. This is the only information you must provide to create an account with us. You may also choose to provide other types of information, such as an account photo and your mobile telephone number for you to enable certain account features, for example, for login verification and mobile notifications from the Service. By removing your mobile number, you will opt out of these account features. For a carer to communicate with a care provider using Memaxi PRO, the carer needs to register his social security number in Memaxi before communication can take place.
The PRO client will create accounts for its carers based on username and password or social security number.
To create a Profile in Memaxi, you need to supply a name as a minimum and associate your Profile with a registered Memaxi user account. Optionally, you can provide a profile photo for the Profile.
PRO clients create Profiles for their Beneficiaries of Care based on social security number. Optionally, Beneficiaries as Data Subjects may agree on a registered Profile photo to be used for secure video communication in lieu of LoA4 user authentication (electronic certification issued on mobile SIM cards).
Private, health and other special categories of personal data
As part of the Profile you or a Memaxi registered user as authorised by you or legally responsible for you may enter, upload and store information relating to your daily schedule, life events, assistance needed for daily living etc. We do not process this information in any way other than to communicate it to Memaxi registered users with appropriate access permissions and as authorized by you, in your best interest.
Marketing and support queries
We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt in/out of these communications from us by following the unsubscribe link or instructions provided in any e-mail we send.
If you contact us via e-mail, by phone or via social media, we may keep your e-mail message, e-mail address, phone number, social media handle and other and contact information to respond to your request.
Exchange of personal data
We may share or disclose your information at your direction, such as when you authorize a third-party web client or application such as official health care or welfare software systems to access your Profile. Such exchange will be based on means of electronically identifiable information relating to your person, such as your social security number.
Information we receive from your use of our Service:
We may collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device ("Usage Data").
This Usage Data may include information such as your device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When you access the Service by or through a mobile device, this Usage Data may include information about your download and installation of our Service and the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.
We may use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customise our Service.
You can enable or disable location Service when you use our Service at any time, through your device settings.
Tracking & Cookies data
Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies that we may also use are beacons, tags, and scripts to collect and track information and to improve and analyse our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Examples of Cookies we use:
- Session Cookies. We use Session Cookies to operate our Service.
- Preference Cookies. We use Preference Cookies to remember your preferences and various settings.
- Security Cookies. We use Security Cookies for security purposes.
"Do Not Track" Signals
Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
In general, we do not make use of Do Not Track apart from a cookie that we install on your web browser to keep track of your log in and authentication status.
Memaxi is active on social media (Facebook, LinkedIn, Instagram, Snapchat, YouTube), and when you interact with Memaxi there, you make data available to us and the social media provider, for example when you react to our posts, comment on them or share them. We also process your data when you like our page or follow us.
The legal basis for the processing is Memaxi’s legitimate interest in the marketing of Memaxi on social medias, cf. Art. 6, para 1, lit f of the GDPR.
Social media platforms used for our marketing purposes have no access to any of your personal or usage data that you provide to us through using our Services.
Use of data
Memaxi ehf uses the collected data for various purposes:
- To provide and maintain our Service in your interest
- To notify you about changes to our Service
- To allow you to participate in interactive features of our Service when you choose to do so
- To provide customer support
- To gather analysis or valuable information so that we can improve our Service
- To monitor the usage of our Service
- To detect, prevent and address technical issues
- To provide you with news, exclusive offers and general information about other goods, Service and events which we offer that are like those that you have already purchased or enquired about unless you have opted not to receive such information
LEGAL BASIS FOR PROCESSING PERSONAL DATA
The General Data Protection Regulation (GDPR) specifies the need for a legal basis for processing personal data.
Memaxi ehf may process your Personal Data because:
- We need to perform a contract with you
- You have given us permission to do so
- For payment processing purposes
- The processing is in our legitimate interests and it is not overridden by your rights
- To comply with the law
Our PRO clients Data Controllers under the GDPR have a lawful basis for collecting personal data. In this regard Memaxi ehf acts as a Data Processor.
RETENTION OF DATA
Memaxi ehf will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
TRANSFER OF DATA
Memaxi transfers data outside the EU/EEA when you use the Service when parts of the Service are carried out by our data processors, see section on SERVICE PROVIDERS.
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
If you access the Service from a country outside the EU/EEA, the data is made available to a third country, even though your personal data is stored with the EU/EEA. The legal basis for this transfer is based on Article 49, para. 1, lit. b and lit. c in the GDPR.
DISCLOSURE OF DATA
Disclosure for Law Enforcement
Under certain circumstances, Memaxi ehf may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Memaxi ehf may disclose your Personal Data in the good faith belief that such action is necessary to:
- To comply with a legal obligation
- To protect and defend the rights or property of Memaxi ehf
- To prevent or investigate possible wrongdoing in connection with the Service
- To protect the personal safety of users of the Service or the public
- To protect against legal liability
SECURITY OF DATA
The security of your data is important to us but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
YOUR DATA PROTECTION RIGHTS
If you are a resident of the European Union (EU)/European Economic Area (EEA), you have certain data protection rights. Memaxi ehf aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
Please note that when a Memaxi PRO client as a care provider and as a Data Controller holds information about you in Memaxi, you need to contact that entity.
In certain circumstances, you have the following data protection rights:
- The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
- The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right to object. You have the right to object to our processing of your Personal Data.
- The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
- The right to withdraw consent. You also have the right to withdraw your consent at any time where Memaxi ehf relied on your consent to process your personal information.
- Please note that we may ask you to verify your identity before responding to such requests.
- You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the EU/EEA.
We engage third party companies and individuals to facilitate our Service ("Service Providers"), to perform functions, provide the Service on our behalf, to perform Service-related Service or to assist us in analysing how our Service is used. These Service Providers are based in Iceland, in the EU/EEA, in the United States and other countries and are bound by a contract with us that ensures your data is managed in accordance with EU/EEA Data Protection laws.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Our Service is a SaaS Service (Software-As-A-Service) and is centrally hosted in a network of data centres. Our hosting provider runs, supports and backs up our Service as requested by us.
We may provide paid products and/or Service within the Service. In that case, we use third-party Services for payment processing (e.g. payment processors).
The payment processors we work with are:
We may provide video calls through third-party video Services or third-party components built into our Service.
Text messaging and e-mail notifications
We may provide text messaging and notifications through third-party messaging Service or third-party components built into our Service.
Facial recognition and facial liveness detection
We may provide facial recognition and facial liveness through a third-party processing Service or third-party components built into our Service. No photos are stored by these services and only used to extract patterns for comparison, which are not stored either.
We may use third-party Service Providers to monitor and analyse the use of our Service.
We use Google Analytics as a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google Services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: http://www.google.com/intl/en/policies/privacy/
Links to other web sites
Our Service may contain links to third-party web sites or services that are not owned or controlled by Memaxi ehf. Memaxi ehf has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third-party web sites or services other than Memaxi’s data sub-processors (see under PERSONAL DATA).
You further acknowledge and agree that Memaxi ehf shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods or services available on or through any such web sites or services.
We strongly advise you to read the terms and conditions and privacy policies of any third-party web sites or services that you visit.
We do not knowingly allow children under the age of 18 to create a user account in Memaxi to serve as carers. We ask if the user signing up is over the age of 18 during the registration process.
When a Profile is created for a person under the age of 18 we do our best to seek consent from the parent or guardian of that person. If the person for whom the Profile is intended is under the age of 18 we ask the parent or guardian to first create a user account in Memaxi and then confirm that this user is the parent or guardian before collecting any personal information for the child. If we do not receive this consent, it will not be possible to use the Profile and we take steps to remove that information from our servers.
If you believe Personal Data is being collected in Memaxi relating to your child and you or another parent/guardian have NOT received an email providing notice or seeking your consent, please feel free to contact us at firstname.lastname@example.org. If we become aware that we have collected Personal Data from children without verification of parental consent, we shall take steps to remove that information from our servers.
COMPLAINT TO A SUPERVISORY AUTHORITY
If you have any concerns or complaints about our processing of your personal data, feel free to contact us by e-mail on email@example.com
You as a data subject have the right to submit a complaint to your supervisory authority.
The supervisory authority in Iceland is the Icelandic Data Protection Agency:
https://www.personuvernd.is, tel. (+354) 510 9600, e-mail firstname.lastname@example.org.