Privacy & Data Protection

Privacy Policy

Effective Date: 01 August 2025  ·  AiCenna Digital Health Platform  ·  info@aicenna.com

About AiCenna: AiCenna is a digital health technology platform that uses artificial intelligence (AI) and digital twin technologies to support health monitoring, personalized wellness insights, and clinical decision support. Your privacy is a priority. This policy outlines how we collect, use, share, and protect your personal information in compliance with HIPAA (U.S.), CCPA (U.S.), and GDPR (EU).

Medical disclaimer: Unless expressly stated otherwise, AiCenna’s AI-generated outputs are designed to assist users and healthcare professionals and are not a substitute for independent medical judgment, diagnosis, or treatment decisions.

Information we collect

We may collect the following types of data when you use our services:

  • Personal information — Name, email address, and account credentials.
  • Health & biosensing data — Data from sensors, wearables, and other connected devices.
  • Genomic data — DNA and methylation data you voluntarily provide.
  • Digital twin data — Health models, longitudinal health profiles, predictive insights, simulation outputs, and other derived information generated by the AiCenna platform using your authorized health data.
  • Technical data — IP address, browser type, device identifiers, and usage logs.

Legal bases for processing (GDPR)

We process personal data under one or more of the following legal bases:

Consent

When you connect wearable or genomic data to the platform.

Contractual necessity

To deliver the services you have requested from us.

Legitimate interest

To improve, secure, and optimize the AiCenna platform.

Legal obligation

To comply with applicable laws and regulatory requirements.

HIPAA compliance (U.S. users)

For users in the United States, we comply with the Health Insurance Portability and Accountability Act (HIPAA):

  • We implement administrative, physical, and technical safeguards to protect your Protected Health Information (PHI).
  • We enter Business Associate Agreements (BAAs) when working with healthcare providers.
  • PHI is encrypted, access-controlled, and shared only with authorized parties.

How we use your data

  • Deliver personalized AI health insights and digital twin simulations.
  • Provide tailored health and wellness recommendations.
  • Conduct research and development (R&D) using anonymized or de-identified data only.
  • Fulfill legal, regulatory, and compliance obligations.

AI processing disclaimer: AI-generated summaries, recommendations, and digital twin insights are designed to support health monitoring and clinical decision-making. They should not be relied upon as the sole basis for diagnosis, treatment, or emergency medical decisions. Always consult a qualified healthcare professional for clinical guidance.

Data sharing

We do not sell your personal data. We may share your data only in the following circumstances:

  • With your explicit consent — For example, with authorized healthcare providers you nominate.
  • With trusted service providers — Including cloud hosting, analytics, and AI infrastructure, under strict confidentiality agreements.
  • With regulators — When required by law or to comply with legal processes.

Your rights

You have the following rights regarding your personal data. Rights available to you may vary depending on your jurisdiction.

Access & correction

Request access to or correction of the data we hold about you.

Deletion

Request deletion of your data, subject to legal and medical record-keeping requirements.

Data portability

Request a copy of your data in a machine-readable format.

Withdraw consent

Opt out of non-essential data processing at any time.

EU residents: To exercise your rights under the GDPR, email us at info@aicenna.com. We aim to respond within 30 days.

Data security

We implement strong security measures to protect your information:

  • Encryption of data both in transit and at rest.
  • Role-based access controls and detailed audit logs.
  • Continuous monitoring and regular vulnerability assessments.

Security limitation: While we employ commercially reasonable administrative, technical, and organizational safeguards, no method of electronic transmission or storage can be guaranteed to be completely secure. We encourage you to protect your account credentials and report any suspected unauthorized access to us promptly.

International data transfers

Your data may be processed in the United States, United Arab Emirates (UAE), and Pakistan. We rely on Standard Contractual Clauses (SCCs) and other lawful safeguards to ensure adequate protection for data transferred outside the EU/EEA.

United States United Arab Emirates Pakistan Standard Contractual Clauses (SCCs)

Children's privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately so we can delete it.

Updates to this policy

We may update this Privacy Policy periodically. When we do, we will revise the effective date at the top of this page. Continued use of our services after any changes indicates your acceptance of the updated policy. We encourage you to review this page regularly to stay informed.

Contact us

For questions, concerns, or to exercise your privacy rights, please reach out to our privacy team.

AiCenna Privacy Team

We respond to all privacy requests within 30 days.

info@aicenna.com