ElderOS Vision — Privacy Policy

Effective date: June 16, 2026
Last updated: June 16, 2026

Introduction

This Privacy Policy explains how ServeIQ Inc. ("ServeIQ," "we," "us," or "our") handles personal information in connection with the ElderOS Vision mobile application for Android (the "App").

ElderOS Vision is a business-to-business (B2B) safety-monitoring tool used inside long-term care (LTC) facilities. On-site sensors (an AI camera and radar connected to a facility edge device) detect resident safety events — such as falls, on-floor events, and bed-exits — and the App pushes real-time alerts to the mobile phones of facility staff so they can respond quickly.

The App is distributed privately to staff at contracted LTC facilities. It is not available to the general public, and it is intended only for authorized facility staff (personal support workers, nurses, supervisors, and administrators). Residents do not use the App. Residents are monitored by the facility's on-site sensors; they do not log in or interact with the App.

This policy describes two groups of people whose information is involved: (a) staff users who log in to the App, and (b) residents who are monitored by the facility's sensors. The role each party plays — and who controls resident health information — is explained under Scope & Roles (PHIPA).

Who We Are

The App is published by ServeIQ Inc., located in Thornhill, Ontario, Canada.

For questions about this policy or about how the App handles staff information, contact us using the details above. Requests about resident health information are handled by the facility (see Scope & Roles (PHIPA) and Your Rights).

Scope & Roles (PHIPA)

This policy applies to the ElderOS Vision App and to ServeIQ's processing of information in connection with the App and the broader ElderOS monitoring service.

Under Ontario's Personal Health Information Protection Act, 2004 ("PHIPA"):

Because the facility is the custodian, resident health information is governed primarily by the facility's privacy policies and its agreement with ServeIQ. Resident-related requests (access, correction, complaints, or deletion) are routed through the facility, as described under Your Rights.

Information We Collect

Information the App collects from staff users

Information the broader system processes (for transparency)

The following information is captured and processed by the facility's on-site sensors and the ElderOS servicenot collected through the mobile App, and not accessible to staff as raw data through the App. We describe it here for transparency:

Some of the information above relates to a resident's health or safety and is therefore sensitive. It is handled on the facility's behalf as described under Scope & Roles (PHIPA).

Data disclosure summary (Google Play)

The categories below summarize the personal and sensitive data associated with the App.

Categories of data — collected, used, and shared
Data category Collected by the App? Used for Shared with
Personal identifiers (name, work email, role, facility/unit) Yes Account setup, authentication, alert routing Facility (custodian); ServeIQ private cloud (Canada)
Authentication token (JWT) Yes Keeping you securely signed in Not shared externally
Device push token (FCM) Yes Delivering push alerts Google / Firebase Cloud Messaging (United States)
Phone number (for staff who receive SMS escalation) Yes SMS alert escalation Twilio (United States)
App activity & diagnostics (alert actions, timestamps, device/OS info, notification status) Yes Service delivery, reliability, diagnostics ServeIQ private cloud (Canada)
Health information — resident safety events and related data (pose/skeleton, event metadata, optional clips) No — processed by facility sensors/service; surfaced in alerts the App receives Safety monitoring and alerting on the facility's behalf Facility (custodian); ServeIQ private cloud (Canada); alert content also via Google FCM and Twilio (United States)
Health information. Because the service detects and reports resident safety events (such as falls, on-floor events, and bed-exits), it processes health-related personal information. This corresponds to the "Health and fitness / Health info" data type under Google Play's Data Safety taxonomy and to "personal health information" under PHIPA. This health information is processed on the facility's behalf, as described under Scope & Roles (PHIPA).

We do not sell personal information, do not use it for advertising, and do not share it for cross-app tracking. See How Information Is Shared.

How We Use Information

We use the information collected through the App to:

We do not use personal information for advertising, we do not sell it, and we do not use it to track users across other apps or services.

How Information Is Shared

Service providers (sub-processors)

We share limited information with the following service providers, only as needed to operate the service:

Sub-processors
Sub-processorPurpose
Google Firebase Cloud Messaging — Google LLC (United States)Push-notification delivery to staff devices
Twilio Inc. (United States)SMS alert escalation (uses staff phone numbers)
Microsoft 365 — Microsoft CorporationEmail alert delivery
ServeIQ private cloud (Montréal, Canada)Cloud hosting and data storage

Service providers are permitted to use the information only to perform services for us and under appropriate contractual safeguards.

Cross-border processing of alert content (important). To enable an immediate response, real-time alerts — including push notifications, SMS messages, and email — can contain resident-identifying information, such as the event type and the resident's room and/or name (for example, "Fall — Room 101"). Push notifications are delivered by Google (Firebase Cloud Messaging) and SMS messages by Twilio, both of which operate in the United States. As a result, the content of these alerts — together with device push tokens and staff phone numbers — is transmitted to and processed in the United States for the purpose of delivering the alert. This processing is carried out on the facility's behalf and under our agreement with the facility. Each facility, as the Health Information Custodian, is responsible for ensuring its resident consent and PHIPA obligations address this cross-border processing of personal health information.

The facility (Health Information Custodian)

Information processed through the service is made available to the contracting LTC facility, which is the custodian of its residents' health information and the employer of the staff users.

Legal and safety disclosures

We may disclose information if required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, safety, or property of residents, staff, the facility, ServeIQ, or others.

What we never do: We do not sell personal information, we do not share it with advertising networks or data brokers, and we do not share it for cross-app tracking.

Data Storage & Security

We use technical and organizational measures designed to protect personal information, including:

No method of transmission or storage is completely secure, but we work to protect personal information using industry-standard safeguards. The data flow is: on-site edge device → ServeIQ cloud (Canada) → staff mobile App over HTTPS, with push notifications delivered through Firebase Cloud Messaging (Google).

Data Residency

ServeIQ hosts and processes personal information for the service on its private cloud located in Montréal, Canada. Our application and database servers are located in Canada.

Exception — message delivery. Push notifications are delivered by Google (Firebase Cloud Messaging) and SMS messages by Twilio, both of which operate in the United States. Device push tokens, staff phone numbers, and the content of alert notifications (which can include resident-identifying information) are therefore processed in the United States for the purpose of delivering alerts. Email alerts are delivered through Microsoft 365. See How Information Is Shared for details on this cross-border processing.

Data Retention & Deletion

How to request deletion

Staff users may request deletion of their account data by emailing [email protected] or by contacting their facility administrator. Requests relating to resident health information must be made through the facility, which is the custodian of that information (see Your Rights). We will respond to verified requests within a reasonable time and in accordance with applicable law.

Your Rights

Staff users. You may request to access, correct, or delete your account information by contacting ServeIQ at [email protected] or by contacting your facility.

Residents and their substitute decision-makers. Requests to access, correct, or otherwise exercise rights over resident personal health information are handled by the facility as the Health Information Custodian under PHIPA. Please direct these requests to the facility; ServeIQ will support the facility in responding as its service provider.

You may also have the right to make a complaint to the Information and Privacy Commissioner of Ontario (IPC): 2 Bloor Street East, Suite 1400, Toronto, Ontario M4W 1A8; toll-free 1-800-387-0073 or 416-326-3333; www.ipc.on.ca.

Children's Privacy

The App is a workplace tool for adult facility staff. It is not directed to children, and it is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children through the App.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, the "Effective date." If we make material changes, we will provide notice by posting the updated policy at this URL and by notifying contracting facilities by email. Your continued use of the App after an update takes effect constitutes acceptance of the revised policy, to the extent permitted by law.

Contact Us

For privacy questions or requests relating to the App or staff information, contact:

Requests relating to resident personal health information should be directed to the facility, which is the Health Information Custodian. Please contact the privacy contact identified by your facility.