ElderOS Vision — Privacy Policy
Effective date: June 16, 2026
Last updated: June 16, 2026
Introduction
This Privacy Policy explains how ServeIQ Inc. ("ServeIQ," "we," "us," or "our") handles personal information in connection with the ElderOS Vision mobile application for Android (the "App").
ElderOS Vision is a business-to-business (B2B) safety-monitoring tool used inside long-term care (LTC) facilities. On-site sensors (an AI camera and radar connected to a facility edge device) detect resident safety events — such as falls, on-floor events, and bed-exits — and the App pushes real-time alerts to the mobile phones of facility staff so they can respond quickly.
The App is distributed privately to staff at contracted LTC facilities. It is not available to the general public, and it is intended only for authorized facility staff (personal support workers, nurses, supervisors, and administrators). Residents do not use the App. Residents are monitored by the facility's on-site sensors; they do not log in or interact with the App.
Who We Are
The App is published by ServeIQ Inc., located in Thornhill, Ontario, Canada.
- Publisher / data processor: ServeIQ Inc.
- Mailing address: 125 Commerce Valley Dr. W., Suite 802, Thornhill, Ontario L3T 7V9, Canada
- Privacy contact: [email protected]
For questions about this policy or about how the App handles staff information, contact us using the details above. Requests about resident health information are handled by the facility (see Scope & Roles (PHIPA) and Your Rights).
Scope & Roles (PHIPA)
This policy applies to the ElderOS Vision App and to ServeIQ's processing of information in connection with the App and the broader ElderOS monitoring service.
Under Ontario's Personal Health Information Protection Act, 2004 ("PHIPA"):
- The LTC facility is the Health Information Custodian (HIC). The facility controls the personal health information of its residents, determines the purposes for which that information is collected and used, and is responsible for resident consent, access, and correction.
- ServeIQ acts as the facility's service provider and agent. We process information on the facility's behalf and at its direction, under a written agreement, solely to provide and support the monitoring and alerting service. We do not use resident health information for our own purposes.
Information We Collect
Information the App collects from staff users
- Identity and account details: name, work email address, assigned role, and assigned facility/unit.
- Authentication data: an authentication token (JWT) used to keep you securely signed in.
- Device push token: a Firebase Cloud Messaging (FCM) token used to deliver alerts to your device.
- App activity and diagnostics: records of alerts viewed, acknowledged, attended, and resolved, along with timestamps; device and operating-system information used for delivery and diagnostics; and your notification-permission status.
Information the broader system processes (for transparency)
The following information is captured and processed by the facility's on-site sensors and the ElderOS service — not collected through the mobile App, and not accessible to staff as raw data through the App. We describe it here for transparency:
- Camera-derived pose/skeleton data and safety-event metadata for monitored residents.
- Optional short event video or image clips, retained according to the facility's consent and retention settings.
- Resident profile data managed by the facility (for example, name, room, and risk indicators).
Data disclosure summary (Google Play)
The categories below summarize the personal and sensitive data associated with the App.
| Data category | Collected by the App? | Used for | Shared with |
|---|---|---|---|
| Personal identifiers (name, work email, role, facility/unit) | Yes | Account setup, authentication, alert routing | Facility (custodian); ServeIQ private cloud (Canada) |
| Authentication token (JWT) | Yes | Keeping you securely signed in | Not shared externally |
| Device push token (FCM) | Yes | Delivering push alerts | Google / Firebase Cloud Messaging (United States) |
| Phone number (for staff who receive SMS escalation) | Yes | SMS alert escalation | Twilio (United States) |
| App activity & diagnostics (alert actions, timestamps, device/OS info, notification status) | Yes | Service delivery, reliability, diagnostics | ServeIQ private cloud (Canada) |
| Health information — resident safety events and related data (pose/skeleton, event metadata, optional clips) | No — processed by facility sensors/service; surfaced in alerts the App receives | Safety monitoring and alerting on the facility's behalf | Facility (custodian); ServeIQ private cloud (Canada); alert content also via Google FCM and Twilio (United States) |
We do not sell personal information, do not use it for advertising, and do not share it for cross-app tracking. See How Information Is Shared.
How We Use Information
We use the information collected through the App to:
- authenticate staff users and keep their sessions secure;
- deliver real-time safety alerts to the correct staff devices;
- route, escalate, and track alert handling (viewed, acknowledged, attended, resolved);
- send escalation messages by SMS and email where configured by the facility;
- operate, maintain, troubleshoot, and improve the reliability of the service;
- provide customer and technical support to the facility and its staff;
- protect the security and integrity of the service and investigate misuse; and
- comply with legal obligations and the facility's instructions as our customer and custodian.
We do not use personal information for advertising, we do not sell it, and we do not use it to track users across other apps or services.
How Information Is Shared
Service providers (sub-processors)
We share limited information with the following service providers, only as needed to operate the service:
| Sub-processor | Purpose |
|---|---|
| Google Firebase Cloud Messaging — Google LLC (United States) | Push-notification delivery to staff devices |
| Twilio Inc. (United States) | SMS alert escalation (uses staff phone numbers) |
| Microsoft 365 — Microsoft Corporation | Email alert delivery |
| ServeIQ private cloud (Montréal, Canada) | Cloud hosting and data storage |
Service providers are permitted to use the information only to perform services for us and under appropriate contractual safeguards.
The facility (Health Information Custodian)
Information processed through the service is made available to the contracting LTC facility, which is the custodian of its residents' health information and the employer of the staff users.
Legal and safety disclosures
We may disclose information if required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, safety, or property of residents, staff, the facility, ServeIQ, or others.
Data Storage & Security
We use technical and organizational measures designed to protect personal information, including:
- Encryption in transit: data exchanged between the edge device, our cloud, and the App is protected using TLS (HTTPS).
- Encryption at rest: event clips are encrypted at rest on the on-site edge device using AES-256-GCM (256-bit AES).
- Role-based access control: access to data is limited based on a user's role and assignment.
- Multi-tenant isolation: each facility's data is logically separated from other facilities' data.
- Restricted access: access is limited to authorized facility staff and to ServeIQ support personnel under controlled conditions, for support and maintenance purposes only.
No method of transmission or storage is completely secure, but we work to protect personal information using industry-standard safeguards. The data flow is: on-site edge device → ServeIQ cloud (Canada) → staff mobile App over HTTPS, with push notifications delivered through Firebase Cloud Messaging (Google).
Data Residency
ServeIQ hosts and processes personal information for the service on its private cloud located in Montréal, Canada. Our application and database servers are located in Canada.
Data Retention & Deletion
- Staff account data is retained for the term of the service contract with the facility.
- Event clips and sensor data. By default, raw event video (MP4) is retained for 48 hours and keypoint/pose data (JSON) for 7 days, after which it is automatically deleted. A facility may configure a shorter or longer retention period within the limits permitted by its agreement, its consent settings, and applicable law.
- Deletion: personal information is deleted, anonymized, or returned upon a valid request, or upon termination of the service contract, subject to any legal retention obligations.
How to request deletion
Staff users may request deletion of their account data by emailing [email protected] or by contacting their facility administrator. Requests relating to resident health information must be made through the facility, which is the custodian of that information (see Your Rights). We will respond to verified requests within a reasonable time and in accordance with applicable law.
Your Rights
Staff users. You may request to access, correct, or delete your account information by contacting ServeIQ at [email protected] or by contacting your facility.
Residents and their substitute decision-makers. Requests to access, correct, or otherwise exercise rights over resident personal health information are handled by the facility as the Health Information Custodian under PHIPA. Please direct these requests to the facility; ServeIQ will support the facility in responding as its service provider.
You may also have the right to make a complaint to the Information and Privacy Commissioner of Ontario (IPC): 2 Bloor Street East, Suite 1400, Toronto, Ontario M4W 1A8; toll-free 1-800-387-0073 or 416-326-3333; www.ipc.on.ca.
Children's Privacy
The App is a workplace tool for adult facility staff. It is not directed to children, and it is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children through the App.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, the "Effective date." If we make material changes, we will provide notice by posting the updated policy at this URL and by notifying contracting facilities by email. Your continued use of the App after an update takes effect constitutes acceptance of the revised policy, to the extent permitted by law.
Contact Us
For privacy questions or requests relating to the App or staff information, contact:
- ServeIQ Inc.
- 125 Commerce Valley Dr. W., Suite 802, Thornhill, Ontario L3T 7V9, Canada
- Email: [email protected]
Requests relating to resident personal health information should be directed to the facility, which is the Health Information Custodian. Please contact the privacy contact identified by your facility.