Scope
This policy applies to personal data we collect through the HiiHealth website at hii.health (the “Site”), our early-access programme, our communications with you, and — when released — the HiiHealth mobile application (the “App”). Participation in formal research studies is governed by separate, study-specific consent documents that supplement this policy.
Personal data we collect
Data you give us. When you request early access, contact us, or express interest in partnering, we collect the details you provide: typically your name, email address, organisation, and the content of your message.
Technical and usage data. When you use the Site, we collect limited technical data such as IP address, browser and device type, pages visited, and referral source, through cookies and similar technologies (see Section 10).
Camera and physiological data (App). The App uses your device’s front camera to read physiological signals from short facial video captures. Our design commitments for this data are:
- Facial video is processed on your device. Raw video and facial imagery are not uploaded to, or stored on, HiiHealth servers.
- Only derived signal values (for example a hydration score, a biological-age estimate, or a risk signal, together with capture timestamps and basic quality metrics) are retained, and are stored on your device by default.
- Derived values are synced to our servers only if you create an account and enable sync, and you can delete synced data at any time.
- We do not use facial captures to identify you or for facial recognition.
Research data. If you enrol in a research study, we collect the data described in that study’s consent form. Research datasets shared with partner institutions are de-identified or coded before sharing.
How we use personal data
- To operate, secure, and improve the Site and the App;
- To manage the early-access programme and notify you about availability;
- To respond to enquiries and partnership requests;
- To conduct research and development of our digital biomarkers, using consented or de-identified data;
- To analyse aggregate usage of the Site so we can improve it;
- To meet legal and regulatory obligations.
We do not sell personal data, and we do not share individually identifiable physiological data with advertisers, insurers, or employers.
Consent and its withdrawal
We collect, use, and disclose personal data with your consent, including consent deemed to be given under the PDPA when you voluntarily provide data for an obvious purpose, or under other bases permitted by the PDPA (such as the business-improvement and legitimate interests exceptions, applied narrowly).
You may withdraw consent at any time by contacting our Data Protection Officer (Section 12) or using in-product controls once the App is available. We will explain the likely consequences of withdrawal — for example, that we can no longer keep you on the early-access list — and will stop the relevant collection, use, or disclosure within a reasonable time.
Disclosure of personal data
We disclose personal data only:
- To service providers who process data on our behalf (hosting, email delivery, analytics), bound by contractual obligations of confidentiality and data protection;
- To research partners, in de-identified or coded form, under research agreements and applicable ethics approvals;
- Where required by law, regulation, court order, or a government authority with jurisdiction;
- In connection with a bona fide corporate transaction (such as a financing, acquisition, or reorganisation), subject to the PDPA’s business asset transaction provisions.
International transfers
Our infrastructure providers may store or process data outside Singapore. Where personal data is transferred overseas, we comply with the PDPA’s transfer limitation obligation by ensuring the recipient is bound by legally enforceable obligations (such as contractual clauses) to provide a standard of protection comparable to the PDPA.
Retention
We retain personal data only for as long as it is needed for the purposes described above or as required by law, and we cease to retain it (or anonymise it) once retention no longer serves those purposes. Early-access contact data is deleted on request. Derived signal data that you delete from your account is removed from our active systems and purged from backups on their normal rotation cycle.
Security
We protect personal data with technical and organisational measures appropriate to its sensitivity, including encryption in transit and at rest, access controls, and least- privilege practices. No method of transmission or storage is completely secure; if we discover a data breach that is notifiable under the PDPA, we will assess it and notify the Personal Data Protection Commission (“PDPC”) and affected individuals as required by Part 6A of the PDPA.
Your rights
Under the PDPA you may:
- Access — request a copy of the personal data we hold about you and information about how it has been used or disclosed in the past year;
- Correction — ask us to correct an error or omission in your personal data;
- Withdrawal — withdraw consent as described in Section 04.
We will respond to access and correction requests as soon as reasonably possible and within the timeframes contemplated by the PDPA. We may charge a reasonable fee for access requests where the PDPA permits. If you are dissatisfied with our response, you may complain to the PDPC (www.pdpc.gov.sg).
Data Protection Officer
Our Data Protection Officer can be reached at service.hiihealth@gmail.com (attention: Data Protection Officer) or by post at: Data Protection Officer, HiiHealth Pte Ltd, Singapore.
Other matters
Marketing calls and messages. We will not send telemarketing messages to Singapore telephone numbers except in accordance with the Do Not Call provisions of the PDPA and, for electronic messages, the Spam Control Act.
Children. The Site and early-access programme are not directed at persons under 18, and we do not knowingly collect their personal data. If you believe a minor has provided us personal data, contact our DPO and we will delete it.
Third-party sites. The Site may link to third-party websites whose privacy practices we do not control; their policies, not this one, govern those sites.
Changes. We may update this policy from time to time. Material changes will be flagged on this page with a revised “last updated” date, and — where the change concerns App data — through in-product notice.