Privacy policy
Memaxi ehf

Last updated: September 24 2020
Effective date and version: September 24 2020, version 4.0

We at Memaxi ehf ("us", "we", or "our") are committed to providing quality service to you. We appreciate that you are trusting us with information that is personal and important to you and we do our best to keep your information safe and only use it your best interest.

Memaxi is a care and communications solution and offered as a subscription-based solution (“Service”) for beneficiaries of care and their informal (family) and professional carers. It is used to help manage person-centered care plans, increase communication with the beneficiary with the use of video calls and photos and plan and record care and assistance provided. 

Most of the information you and your carers provide to us through Memaxi is used to help you go about your daily life and keeping this information private is of utmost importance.

In this Privacy Policy we describe the privacy practices for our ‘Service’. We inform you about the data we collect, how we use it, the legal basis for processing your data, it’s retention and transfer, disclosure of information when you use our Service and the measures we take to keep your data secure. We also inform you of your data protection rights and the choices you have associated with that information and our relationship with our service providers. In this Privacy Policy you will also find our disclaimer, how you can provide feedback and, if needed, make a complaint to a supervisory authority.

Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms of Use.

This Privacy Policy will be published in English but may be translated into additional languages for the convenience of the reader. If this Privacy Policy is published in any language other than English, the English language version will be the governing agreement and shall control interpretation of all matters discussed below.

This Privacy Policy is based on the General Data Protection Regulation 2016/679 (“GDPR”) and Icelandic data protection legislation as Memaxi ehf is incorporated in Iceland. 


DEFINITIONS
Beneficiary (of care) The person requiring care and assistance. The person using Memaxi Display
Carer A registered Memaxi user who has been authorised by the Display Profile Beneficiary to help manage the Display Profile, either a professional carer or informal/family carer
Cookies Cookies are small pieces of data stored on your device (computer or mobile device)
Data Controller Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the way any personal information are, or are to be, processed
Data Processors Data Subject is any living individual who is using our Service and is the subject of Personal Data
Data Subject (or User) Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession)
Personal Data A registered Memaxi user who has been authorised by the Display Profile Beneficiary to help manage the Display Profile, either a professional carer or informal/family carer
Profile A Profile is the collection of information relating to a Beneficiary. It may hold calendar events, notes, photos, guestbook entries and other information relating to the daily life of the person the Display Profile is intended for
Worksite A collection of beneficiary profiles and carers. Available only in Memaxi PRO
Usage Data Usage Data is data collected automatically either generated by using the Service or from the Service infrastructure itself (for example, the duration of a page visit)
Service Service means our devices, applications, software, websites, APIs, products and services, including but not limited to the website www.memaxi.com and its sub-sites, the Memaxi Display, Memaxi Connect and Memaxi Lock mobile applications and the Memaxi Web application operated by Memaxi ehf
Memaxi Connect Mobile application, usually run on smartphones, with access to beneficiary information
Memaxi Display Mobile application, usually run on a tablet computer, with an overview of the beneficiary’s day
Memaxi Web Web application of Memaxi
Memaxi HOME For private use for a beneficiary and their informal carers. For Memaxi HOME, Memaxi ehf acts both as a Data Controller and a Data Processor
Memaxi PRO For professional use of care providers who service multiple beneficiaries. Such care providers act as Data Controllers under the GDPR and Memaxi acts as a Data Processor

INFORMATION COLLECTION AND USE
When you user our Service we collect several types of information for various purposes to provide and improve our Service to you.

Information you provide us with: 

Carer / user account information 
Memaxi HOME:
Some personally identifiable information that can be used to contact or identify you (“Personal Data”) is required to create an account on our Service, such as your name, email address and password. This is the only information you must provide to create an account with us. You may also choose to provide other types of information, such as an account photo and your mobile telephone number for you to enable certain account features, for example, for login verification and mobile notifications from the Service. By removing your mobile number, you will opt out of these account features. For a carer to communicate with a care provider using Memaxi PRO, the carer needs to register his social security number in Memaxi before communication can take place.

Memaxi PRO 
The PRO client will create accounts for its carers based on username and password or social security number.

Profile information 
Memaxi HOME
To create a Profile in Memaxi, you need to supply a name as a minimum and associate your Profile with a registered Memaxi user account. Optionally, you can provide a profile photo for the Profile.

Memaxi PRO 
PRO clients create Profiles for their Beneficiaries of Care based on social security number. Optionally, Beneficiaries as Data Subjects may agree on a registered Profile photo to be used for secure video communication in lieu of LoA4 user authentication (electronic certification issued on mobile SIM cards).

Private, health and other special categories of personal data 
As part of the Profile you or a Memaxi registered user as authorised by you or legally responsible for you may enter, upload and store information relating to your daily schedule, life events, assistance needed for daily living etc. We do not process this information in any way other than to communicate it to Memaxi registered users with appropriate access permissions and as authorized by you, in your best interest.

Marketing and support queries 
We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt in/out of these communications from us by following the unsubscribe link or instructions provided in any e-mail we send.
If you contact us via e-mail, by phone or via social media, we may keep your e-mail message, e-mail address, phone number, social media handle and other and contact information to respond to your request.

Exchange of personal data 
We may share or disclose your information at your direction, such as when you authorize a third-party web client or application such as official health care or welfare software systems to access your Profile. Such exchange will be based on means of electronically identifiable information relating to your person, such as your social security number.

Information we receive from your use of our Service: 

Usage Data 
We may collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device ("Usage Data").
This Usage Data may include information such as your device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When you access the Service by or through a mobile device, this Usage Data may include information about your download and installation of our Service and the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.

Location Data 
We may use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customise our Service.
You can enable or disable location Service when you use our Service at any time, through your device settings.

Tracking & Cookies data 
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.
Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies that we may also use are beacons, tags, and scripts to collect and track information and to improve and analyse our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Examples of Cookies we use:
  • Session Cookies. We use Session Cookies to operate our Service.
  • Preference Cookies. We use Preference Cookies to remember your preferences and various settings.
  • Security Cookies. We use Security Cookies for security purposes.

"Do Not Track" Signals 
Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
In general, we do not make use of Do Not Track apart from a cookie that we install on your web browser to keep track of your log in and authentication status.

Social Media  
Memaxi is active on social media (Facebook, LinkedIn, Instagram, Snapchat, YouTube), and when you interact with Memaxi there, you make data available to us and the social media provider, for example when you react to our posts, comment on them or share them. We also process your data when you like our page or follow us.
The legal basis for the processing is Memaxi’s legitimate interest in the marketing of Memaxi on social medias, cf. Art. 6, para 1, lit f of the GDPR.

Social media platforms used for our marketing purposes have no access to any of your personal or usage data that you provide to us through using our Services. 

Use of data 
Memaxi ehf uses the collected data for various purposes:
  • To provide and maintain our Service in your interest
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer support
  • To gather analysis or valuable information so that we can improve our Service
  • To monitor the usage of our Service
  • To detect, prevent and address technical issues
  • To provide you with news, exclusive offers and general information about other goods, Service and events which we offer that are like those that you have already purchased or enquired about unless you have opted not to receive such information


LEGAL BASIS FOR PROCESSING PERSONAL DATA  
The General Data Protection Regulation (GDPR) specifies the need for a legal basis for processing personal data.
If you are from the European Union (EU) / European Economic Area (EEA), Memaxi ehf legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.

Memaxi HOME 
Memaxi ehf may process your Personal Data because:
  • We need to perform a contract with you
  • You have given us permission to do so
  • For payment processing purposes
  • The processing is in our legitimate interests and it is not overridden by your rights
  • To comply with the law

Memaxi PRO 
Our PRO clients Data Controllers under the GDPR have a lawful basis for collecting personal data. In this regard Memaxi ehf acts as a Data Processor.


RETENTION OF DATA 
Memaxi ehf will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

Memaxi ehf will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.


TRANSFER OF DATA 
Memaxi transfers data outside the EU/EEA when you use the Service when parts of the Service are carried out by our data processors, see section on SERVICE PROVIDERS.
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
If you access the Service from a country outside the EU/EEA, the data is made available to a third country, even though your personal data is stored with the EU/EEA. The legal basis for this transfer is based on Article 49, para. 1, lit. b and lit. c in the GDPR.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Memaxi ehf will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.


DISCLOSURE OF DATA 
Business Transaction
If Memaxi ehf is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Disclosure for Law Enforcement 
Under certain circumstances, Memaxi ehf may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Legal Requirements 
Memaxi ehf may disclose your Personal Data in the good faith belief that such action is necessary to:
  • To comply with a legal obligation
  • To protect and defend the rights or property of Memaxi ehf
  • To prevent or investigate possible wrongdoing in connection with the Service
  • To protect the personal safety of users of the Service or the public
  • To protect against legal liability


SECURITY OF DATA 
The security of your data is important to us but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.


YOUR DATA PROTECTION RIGHTS 
If you are a resident of the European Union (EU)/European Economic Area (EEA), you have certain data protection rights. Memaxi ehf aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.

Please note that when a Memaxi PRO client as a care provider and as a Data Controller holds information about you in Memaxi, you need to contact that entity.

In certain circumstances, you have the following data protection rights: 
  • The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
  • The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
  • The right to object. You have the right to object to our processing of your Personal Data.
  • The right of restriction. You have the right to request that we restrict the processing of your personal information.
  • The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
  • The right to withdraw consent. You also have the right to withdraw your consent at any time where Memaxi ehf relied on your consent to process your personal information.
  • Please note that we may ask you to verify your identity before responding to such requests.
  • You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the EU/EEA.


SERVICE PROVIDERS 
We engage third party companies and individuals to facilitate our Service ("Service Providers"), to perform functions, provide the Service on our behalf, to perform Service-related Service or to assist us in analysing how our Service is used. These Service Providers are based in Iceland, in the EU/EEA, in the United States and other countries and are bound by a contract with us that ensures your data is managed in accordance with EU/EEA Data Protection laws.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Hosting 
Our Service is a SaaS Service (Software-As-A-Service) and is centrally hosted in a network of data centres. Our hosting provider runs, supports and backs up our Service as requested by us.

Payments processors 
We may provide paid products and/or Service within the Service. In that case, we use third-party Services for payment processing (e.g. payment processors).
We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:
  • Apple Store In-App Payments, their Privacy Policy can be viewed at https://www.apple.com/legal/privacy/en-ww/
  • Google Play In-App Payments, their Privacy Policy can be viewed at https://www.google.com/policies/privacy/
  • PayPal or Braintree, their Privacy Policy can be viewed at https://www.paypal.com/webapps/mpp/ua/privacy-full

Video calls 
We may provide video calls through third-party video Services or third-party components built into our Service.

Text messaging and e-mail notifications 
We may provide text messaging and notifications through third-party messaging Service or third-party components built into our Service.

Facial recognition and facial liveness detection 
We may provide facial recognition and facial liveness through a third-party processing Service or third-party components built into our Service. No photos are stored by these services and only used to extract patterns for comparison, which are not stored either.

Analytics 
We may use third-party Service Providers to monitor and analyse the use of our Service.

We use Google Analytics as a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google Services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. 

For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: http://www.google.com/intl/en/policies/privacy/ 


DISCLAIMER 
Links to other web sites
Our Service may contain links to third-party web sites or services that are not owned or controlled by Memaxi ehf. Memaxi ehf has no control over, and assumes no responsibility for, the content, privacy policies, or practices of any third-party web sites or services other than Memaxi’s data sub-processors (see under PERSONAL DATA).

You further acknowledge and agree that Memaxi ehf shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods or services available on or through any such web sites or services. 

We strongly advise you to read the terms and conditions and privacy policies of any third-party web sites or services that you visit. 

Children's privacy 
We do not knowingly allow children under the age of 18 to create a user account in Memaxi to serve as carers. We ask if the user signing up is over the age of 18 during the registration process.
When a Profile is created for a person under the age of 18 we do our best to seek consent from the parent or guardian of that person. If the person for whom the Profile is intended is under the age of 18 we ask the parent or guardian to first create a user account in Memaxi and then confirm that this user is the parent or guardian before collecting any personal information for the child. If we do not receive this consent, it will not be possible to use the Profile and we take steps to remove that information from our servers.
If you believe Personal Data is being collected in Memaxi relating to your child and you or another parent/guardian have NOT received an email providing notice or seeking your consent, please feel free to contact us at info@memaxi.com. If we become aware that we have collected Personal Data from children without verification of parental consent, we shall take steps to remove that information from our servers.


COMPLAINT TO A SUPERVISORY AUTHORITY 
If you have any concerns or complaints about our processing of your personal data, feel free to contact us by e-mail on privacy@memaxi.com
You as a data subject have the right to submit a complaint to your supervisory authority.
The supervisory authority in Iceland is the Icelandic Data Protection Agency:
https://www.personuvernd.is, tel. (+354) 510 9600, e-mail postur@personuvernd.is.


CHANGES TO THIS PRIVACY POLICY 
We reserve the right, at our sole discretion, to modify or replace this Privacy Policy at any time. If we make changes to this Privacy Policy that, in our sole discretion, is material we will notify you of those changes. We will notify you through the Service prior to the change becoming effective and update the "effective date" at the top of this Privacy Policy.
By continuing to access or use our Service after those revisions become effective, you agree to be bound by the revised Privacy Policy. If you do not agree to the revision, you as a HOME user may unsubscribe from the Service by deleting your account. You as a PRO user will need to contact your Memaxi Worksite administrator who created your access to the Service.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on our public website www.memaxi.com and corresponding language versions of that site.


CONTACT  
If you have any questions about this Privacy Policy, please contact us by email on privacy@memaxi.com


   
Heimilisfang

Laugavegur 105
105 Reykjavík, Iceland

Samband

Sími: info@memaxi.com
Netfang: +354 415 2520