Legal

Privacy Policy

Last updated: 14 August 2026

HiiHealth Pte. Ltd. (“HiiHealth”, “we”, “us”) is a Singapore-incorporated company building camera-based physiological sensing technology. Privacy is a design principle of our product, not an afterthought: our architecture is built so that raw facial imagery is processed on your device and does not need to leave it. This policy explains what personal data we collect, why, and how we protect it, in accordance with the Personal Data Protection Act 2012 of Singapore (“PDPA”).

01

Scope

This policy applies to personal data we collect through the HiiHealth website at hii.health (the “Site”), our early-access programme, our communications with you, and — when released — the HiiHealth mobile application (the “App”). Participation in formal research studies is governed by separate, study-specific consent documents that supplement this policy.

02

Personal data we collect

Data you give us. When you request early access, contact us, or express interest in partnering, we collect the details you provide: typically your name, email address, organisation, and the content of your message.

Technical and usage data. When you use the Site, we collect limited technical data such as IP address, browser and device type, pages visited, and referral source, through cookies and similar technologies (see Section 10).

Camera and physiological data (App). The App uses your device’s front camera to read physiological signals from short facial video captures. Our design commitments for this data are:

  • Facial video is processed on your device. Raw video and facial imagery are not uploaded to, or stored on, HiiHealth servers.
  • Only derived signal values (for example a hydration score, a biological-age estimate, or a risk signal, together with capture timestamps and basic quality metrics) are retained, and are stored on your device by default.
  • Derived values are synced to our servers only if you create an account and enable sync, and you can delete synced data at any time.
  • We do not use facial captures to identify you or for facial recognition.

Research data. If you enrol in a research study, we collect the data described in that study’s consent form. Research datasets shared with partner institutions are de-identified or coded before sharing.

03

How we use personal data

  • To operate, secure, and improve the Site and the App;
  • To manage the early-access programme and notify you about availability;
  • To respond to enquiries and partnership requests;
  • To conduct research and development of our digital biomarkers, using consented or de-identified data;
  • To analyse aggregate usage of the Site so we can improve it;
  • To meet legal and regulatory obligations.

We do not sell personal data, and we do not share individually identifiable physiological data with advertisers, insurers, or employers.

06

Disclosure of personal data

We disclose personal data only:

  • To service providers who process data on our behalf (hosting, email delivery, analytics), bound by contractual obligations of confidentiality and data protection;
  • To research partners, in de-identified or coded form, under research agreements and applicable ethics approvals;
  • Where required by law, regulation, court order, or a government authority with jurisdiction;
  • In connection with a bona fide corporate transaction (such as a financing, acquisition, or reorganisation), subject to the PDPA’s business asset transaction provisions.
07

International transfers

Our infrastructure providers may store or process data outside Singapore. Where personal data is transferred overseas, we comply with the PDPA’s transfer limitation obligation by ensuring the recipient is bound by legally enforceable obligations (such as contractual clauses) to provide a standard of protection comparable to the PDPA.

08

Retention

We retain personal data only for as long as it is needed for the purposes described above or as required by law, and we cease to retain it (or anonymise it) once retention no longer serves those purposes. Early-access contact data is deleted on request. Derived signal data that you delete from your account is removed from our active systems and purged from backups on their normal rotation cycle.

09

Security

We protect personal data with technical and organisational measures appropriate to its sensitivity, including encryption in transit and at rest, access controls, and least- privilege practices. No method of transmission or storage is completely secure; if we discover a data breach that is notifiable under the PDPA, we will assess it and notify the Personal Data Protection Commission (“PDPC”) and affected individuals as required by Part 6A of the PDPA.

10

Cookies and analytics

The Site uses strictly necessary cookies and privacy-conscious analytics to understand aggregate usage. You can control cookies through your browser settings; disabling them may affect parts of the Site. We do not use third-party advertising cookies.

11

Your rights

Under the PDPA you may:

  • Access — request a copy of the personal data we hold about you and information about how it has been used or disclosed in the past year;
  • Correction — ask us to correct an error or omission in your personal data;
  • Withdrawal — withdraw consent as described in Section 04.

We will respond to access and correction requests as soon as reasonably possible and within the timeframes contemplated by the PDPA. We may charge a reasonable fee for access requests where the PDPA permits. If you are dissatisfied with our response, you may complain to the PDPC (www.pdpc.gov.sg).

12

Data Protection Officer

Our Data Protection Officer can be reached at service.hiihealth@gmail.com (attention: Data Protection Officer) or by post at: Data Protection Officer, HiiHealth Pte Ltd, Singapore.

13

Other matters

Marketing calls and messages. We will not send telemarketing messages to Singapore telephone numbers except in accordance with the Do Not Call provisions of the PDPA and, for electronic messages, the Spam Control Act.

Children. The Site and early-access programme are not directed at persons under 18, and we do not knowingly collect their personal data. If you believe a minor has provided us personal data, contact our DPO and we will delete it.

Third-party sites. The Site may link to third-party websites whose privacy practices we do not control; their policies, not this one, govern those sites.

Changes. We may update this policy from time to time. Material changes will be flagged on this page with a revised “last updated” date, and — where the change concerns App data — through in-product notice.

Placeholders for incorporation details. This document refers to HiiHealth Pte. Ltd. and a registered address. Before publication, confirm the exact legal entity name, UEN, registered address, and DPO contact, and have this policy reviewed by qualified Singapore counsel.