1. Introduction
HAA Synergy Limited / How AI Assist Limited ("we", "us", or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Synergy Smart Care Platform ("the Platform").
This Policy is prepared in accordance with:
- The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018;
- The EU General Data Protection Regulation (Regulation 2016/679) ("EU GDPR");
- The Privacy and Electronic Communications Regulations (PECR) 2003;
- The European Convention on Human Rights, Article 8 (right to private and family life).
We are the Data Controller for personal data processed through the Platform. Our Data Protection Officer can be contacted via our Contact page.
2. Data We Collect
2.1 Personal Data of Users (Clinicians and Administrators)
- Identity Data: First name, last name, display name;
- Contact Data: Email address, contact number, company/organisation name;
- Authentication Data: Email, hashed password, PIN hash, MFA configuration data;
- Technical Data: IP address (for geofencing), browser type, login timestamps, audit trail;
- Location Data: Country-level geolocation for data residency compliance (UK/EU only).
2.2 Assessment Data (Resident Information)
- Resident Identity: Name, health identifier, age, gender;
- Resident Contact: Email, address;
- Medical Information: Current medical conditions (special category data under Article 9 UK GDPR);
- Care Provider Information: Name, email, contact number;
- Photographic Evidence: Room photographs uploaded for structural analysis;
- Assessment Results: AI-generated vision findings, compliance reports, compiled PDFs.
3. Lawful Basis for Processing
We process personal data under the following lawful bases as set out in Article 6 of UK GDPR:
- Contract (Article 6(1)(b)): Processing necessary to provide the Platform services under our service agreement with your organisation;
- Legal Obligation (Article 6(1)(c)): Compliance with healthcare, building safety, and data protection regulations;
- Legitimate Interests (Article 6(1)(f)): Security monitoring, audit logging, and fraud prevention;
- Consent (Article 6(1)(a)): Where you have provided explicit consent for specific processing activities.
For special category data (health information under Article 9 UK GDPR), we rely on Article 9(2)(h) — processing for the provision of health or social care treatment — and Article 9(2)(b) — processing necessary for the establishment, exercise, or defence of legal claims.
4. How We Use Your Data
We use personal data for the following purposes:
- Providing forensic accessibility assessments and compiled reports;
- Authenticating users and managing access (including MFA and PIN verification);
- Enforcing data residency through IP-based geofencing (UK/EU access only);
- Maintaining an immutable audit trail of all platform actions;
- Sending notifications when assessment reports are compiled;
- Generating de-identified analytics for platform improvement;
- Complying with legal and regulatory obligations.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements:
- User Account Data: Retained for the duration of your organisation's service agreement, plus 6 years for audit purposes;
- Assessment Data: Retained per your organisation's data retention policy, default 7 years (aligned with clinical record retention);
- Audit Logs: Retained for a minimum of 6 years for regulatory compliance;
- Authentication Logs: Retained for 12 months.
You may request early deletion of your personal data, subject to legal retention obligations.
6. Data Sharing and Recipients
We do not sell personal data. We may share data with the following categories of recipients:
- Your Organisation: Assessment Data is accessible to authorised clinicians within your organisation;
- Cloud Infrastructure Providers: Hosting and storage services operating within UK/EU data centres;
- AI Processing Sub-processors: LLM and image analysis providers, with PII redaction applied before processing;
- Regulatory Authorities: Where required by law, court order, or regulatory request.
All sub-processors are bound by Data Processing Agreements (DPAs) compliant with UK GDPR Article 28. A current list of sub-processors is available upon request.
7. International Data Transfers
Personal data is stored and processed within the United Kingdom and European Economic Area (EEA). We enforce IP-based geofencing to restrict Platform access to UK/EU regions, ensuring compliance with data residency requirements.
Where any sub-processor is located outside the UK/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisionsas recognised by the UK Information Commissioner's Office (ICO) and the European Commission.
8. Data Security
We implement industry-standard technical and organisational measures to protect personal data:
- Encryption: AES-256 encryption at rest; TLS 1.3 in transit;
- Access Control: Role-based access (Clinician, Administrator, SuperUser);
- Authentication: Multi-factor authentication (TOTP, Passkey) and mandatory PIN;
- PII Redaction: All AI/LLM prompts are anonymised before processing to remove personally identifiable information;
- Auto-Logout: Sessions automatically terminate after 15 minutes of inactivity;
- Geofencing: IP-based restriction to UK/EU regions;
- Password Policy: Mandatory 90-day password renewal cycle;
- Audit Trail: Immutable logging of all user actions for security monitoring.
9. Your Rights Under UK GDPR and EU GDPR
You have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of your personal data;
- Right to Rectification (Article 16): Correct inaccurate or incomplete data;
- Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten");
- Right to Restriction (Article 18): Restrict processing in certain circumstances;
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format;
- Right to Object (Article 21): Object to processing based on legitimate interests;
- Right to Withdraw Consent (Article 7): Withdraw consent at any time where processing is based on consent;
- Right to Lodge a Complaint: With the UK ICO (ico.org.uk) or your national EU data protection authority.
To exercise any of these rights, please contact us through our Contact page. We will respond within one month as required by Article 12 of UK GDPR.
10. Automated Decision-Making
The Platform uses AI-driven analysis to generate accessibility assessment reports. Under Article 22 of UK GDPR, you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you.
Our AI assessments are decision-support tools — they do not produce legally binding decisions. All assessments must be reviewed and verified by a qualified Authorised Professional before any structural interventions are implemented.
11. Cookies and Tracking
The Platform uses essential cookies necessary for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No consent is required for strictly necessary cookies under PECR Regulation 6.
12. Children's Data
The Platform is intended for use by authorised medical professionals only. We do not knowingly collect data from children under 18. Assessment Data may include information about residents of any age, which is processed under the lawful bases set out in Section 3.
13. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority (UK ICO and/or EU DPA) within 72 hours of becoming aware of the breach, in accordance with Article 33 of UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay (Article 34).
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify Users of material changes via the Platform or by email. The "Last Updated" date at the top of this page indicates when the Policy was last revised.
15. Contact
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection Officer at contact@howaiassist.com or through our Contact page. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local EU data protection authority.