At Nabu AI Pty Ltd (“Nabu,” “Nabu AI,” “us,” “we,” or “our”), our mission is to give everyone access to personalised healthcare. We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Policy describes Nabu’s policies and practices regarding its collection and use of your Personal Data, and sets forth your privacy rights. We recognise that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Policy as we undertake new Personal Data practices or adopt new privacy policies.
This Privacy Policy applies to Personal Data we collect:
Our services (“Services”) are available to Users who visit our website at www.nabucares.ai (the “Website”) or use our mobile app (the “App”). We collect different types of data from you via the Website, compared to the App, as set out in section 4 below.
Some more terms that we use:
“Personal Data” is any data that identifies or relates to you as a particular individual, including information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations.
“Anonymised Data” is data where personally identifiable information has been removed, rendering the data anonymous by stripping out information that would allow an individual’s identity to be determined from the remaining data. Data is “anonymised” to protect the privacy and identity of individuals associated with the data. Anonymized Data is no longer Personal Data.
“Aggregated Data” is data that has undergone a process whereby raw data is gathered and expressed in a summary form for statistical analysis. Raw data can be aggregated over a given time period, across individuals, or both, to provide statistics such as average, minimum, maximum, sum, and count. After the data is aggregated, analysis can be performed to gain insights about particular data sets. When data is aggregated across a number of individuals, the resulting aggregation is considered anonymized such that it is no longer Personal Data.
Nabu AI has appointed an internal data protection officer for you to contact if you have any questions or concerns about Nabu AI’s personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Nabu AI’s data protection officer. Nabu AI’s data protection officer’s name and contact information are as follows:
Nabu AI Pty Ltd
L3, 360 Kent Street, Sydney, NSW, 2000, Australia Attn: Privacy
email: Privacy@NabuCares.ai
Nabu AI Pty Ltd, headquartered in Sydney, Australia, will be the controller of your Personal Data processed in connection with the Services.
We have different names for types of accounts, profiles and roles that you may adopt when using the App:
We may collect Personal Data about you from:
When we say “such as”, “including” or “for example” in this Privacy Policy, we are providing examples, not an exhaustive or closed list.
We may collect the following types of Personal Data:
We collect different types of data from you via the Website, compared to the App. As such, when you are using the App and are logged into your Account, we may collect Account data, Profile data, detailed Health data, and Payment and transactional data. When you are using the Website, we may only collect Contact details (with your consent).
We process Personal Data to operate, improve, understand, and personalise our Services. We use Personal Data for the following purposes:
Service delivery, including to:
General research and development. We may create and use Aggregated Data, Anonymized Data or other anonymous data from Personal Data we collect, including Health Data on the App, for our business purposes, including to analyse the effectiveness of the Services, to improve and add features to the Services, and to analyse the general behaviour and characteristics of Users of the Services. We also use Anonymised Data or Aggregated Data from Health Data on the App for research purposes to help us and our research partners answer important questions about health, wellbeing, advocate support, etc. and create an even better experience for our Users by identifying cutting-edge insights and providing new content and product features.
Research studies. We may use your Personal Data on the App to do a preliminary assessment of your eligibility for our research studies. However, only where specific and informed consent has been given by you may we use your Personal Data including Health Data, in our research studies, for example to analyze your response to certain treatments. The specific purpose for which we use your Personal Data in the context of our research studies will be set out in the informed consent form relating to a particular study.
Marketing and advertising. We do not use personally identifiable Health Data for marketing or advertising purposes. We may use other Personal Data to send you marketing messages as permitted by law or to measure and improve our advertising.
Compliance and protection, including to:
Consequences of not collecting Personal Data: You are not obliged to provide any Personal Data. However, if we do not collect any of your Personal Data, we will not be able to perform the above functions, or provide you with the Services.
We may share your Personal Data on the App with the below third parties, but note that sometimes Health Data is treated differently to other Personal Data (as it is a special category of information):
We use Google Cloud Platform (“GCP”) to host and process data. A list of GCP sub processors can be found here: https://cloud.google.com/terms/subprocessors
We will never sell your Personal Data to anyone. We may gather Aggregated Data or Anonymized Data about our Services or Users, and disclose the results of such aggregated or anonymized data to our partners, service providers, advertisers, and/or other third parties. Such information is no longer Personal Data and can no longer be used to identify you.
How you may share Personal Data through the App: Depending on your use of the App, you may share your Personal Data with any other Account holder, subject to your consent or the consent of the Owner of your profile (in the case of a Dependent). Where you have provided consent for Nabu AI to share your Personal Data with another User, Nabu AI is not responsible for what those Users do with your Personal Data.
Nabu AI has its headquarters in Sydney, Australia, but information we collect about you via the App will be hosted and processed in the United States. By using the App, you acknowledge that your Personal Data will be hosted and processed in the United States.
The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the European General Data Protection Regulation (“GDPR”). Pursuant to Article 46 of the GDPR, Nabu AI is providing appropriate safeguards by ensuring that binding, standard data protection clauses are in place with its hosting and processing service providers, which are enforceable by data subjects in the EU and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved.
Depending on the circumstance, Nabu AI also collects and transfers Personal Data to the U.S. with consent; to perform a contract with you; or to fulfil a compelling legitimate interest of Nabu AI, in a manner that does not outweigh your rights and freedoms. Nabu AI endeavours to apply suitable safeguards to protect the privacy and security of your Personal Data and to use it in a manner only consistent with your relationship with Nabu AI and the practices described in this Privacy Policy.
Where we employ data processors such as Google to process Personal Data on our behalf, we only do so on the basis that such data processors comply with the requirements under the GDPR and have adequate technical measures in place to protect personal information against unauthorised use, loss and theft. Nabu AI enters into data processing agreements and model clauses with such vendors whenever feasible and appropriate. Since it was founded, Nabu AI has received zero government requests for information.
For more information or if you have any questions about data processing in the U.S., please contact us at privacy@nabucares.ai
You have certain rights with respect to your Personal Data, including:
Unless specified otherwise, you can exercise these rights by logging into your account on the App, or by emailing help@nabucares.ai. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardises the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request. Nabu AI will not discriminate against you for exercising your rights.
Storage: In relation to the App, Nabu AI securely stores your data using cloud-based Google infrastructure on data servers in the United States. In relation to the Website, Nabu AI stores any Personal Data obtained from you on a Webflow database in the United States. We, Google and Webflow employ a number of physical, technical, organisational, and administrative security measures designed to protect your Personal Data.
Retention: We retain Personal Data for only as long as reasonably necessary for the purposes associated with such data as described in this Privacy Policy, where we have a business need to do so, or as required by law (e.g., for tax, legal, accounting, or other purposes), whichever is longer. Once this time period has expired, we will delete the data via an automatic deletion process.
To determine the appropriate retention period for your Personal Data, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your Personal Data and whether we can achieve those purposes through other means, and the applicable legal requirements.
All Personal Data that Nabu AI controls may be deleted upon verified request from a User or its authorised agent. For more information on where and how long your Personal Data is stored, and for more information on your rights of erasure and portability, please contact us at privacy@nabucares.ai.
What is a cookie? Cookies are small pieces of data – usually text files – placed on your computer, tablet, phone, or similar device. They can take the form of pixel tags, web beacons, clear GIFs or JavaScript. Cookies are given to your browser by websites you visit, and browsers give these back to the website when you revisit, re-identifying you. They are unique to your account or your browser. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire.
Does Nabu AI use cookies? We do not currently collect or use any cookies on the App; only on our Website.
Strictly Necessary Cookies: These cookies are necessary for the Website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences. You can set your browser to block or alert you about these cookies, but that may cause some parts of the Website to not work (for example, the functionality to opt out of performance cookies). Strictly necessary cookies do not store any personally identifiable information.
Performance Cookies: On the Website, we collect and use analytics tracking cookies from two third parties (namely PostHog and Google Analytics). This is to allow us to understand how users use our Website, by collecting information on how often a user visits certain pages or engages with a particular feature on the Website. We use these aggregated statistics internally to improve the Services.
We also collect and use marketing cookies on the Website. We use Google Analytics for measuring the effectiveness of marketing. This helps us to improve our campaigns and the Services’ content for those who engage with our marketing. To see an overview of the privacy of your Google Analytics cookies, please go here:
https://support.google.com/analytics/answer/6004245.
If you do not allow performance cookies, we will not know when you have visited our Website and will not be able to measure our advertising effectiveness for your visit.
How can you control or delete cookies on the Website? You have the option to disable and delete cookies that may not be necessary for the basic functionality of our website using our consent tool or your browser. Please note that blocking non-essential cookies via your browser (rather than opting out of non-essential cookies using our consent tool) may impact your experience on our Website.
Using our consent tool
When you first visit the Website, you can accept or reject non-essential cookies via the cookie banner. After this, you may adjust your settings by clicking the cookie manager icon in the bottom corner of the website. The cookie manager button looks like this:
Please note that if you first accept non-essential cookies, and then later reject them via the consent tool, you will need to reload the page for those cookies to be dropped.
Using Your Browser
To disable cookies through your browser, follow the instructions usually located within the “Help,” “Tools” or “Edit” menus in your browser. Please note that disabling a cookie or category of cookies does not delete the cookie from your browser unless manually completed through your browser function.
You may install a Google Analytics opt-out browser add-on by going here: https://tools.google.com/dlpage/gaoptout?hl=en-GB.
Cookies Set in the Past
Collection of your data from our analytics cookies can be deleted. If cookies are deleted, the information collected prior to the preference change may still be used. However, we will stop using the disabled cookie to collect any further information from your user experience. For our marketing cookie, when a user opts out of tracking, a new cookie is placed to prevent users from being tracked.
Does Nabu AI respond to Do Not Track Signals? Our App does not use cookies, and therefore Do Not Track browser signals are not relevant. Our Website does not currently obey Do Not Track signals. however, you can manage your cookie preferences as detailed above.
We do not knowingly attempt to solicit or receive information from children.
If you are under 18 or such a greater age of majority as may apply where you live (the “Age of Majority”), please do not attempt to register for the Services or send any Personal Data about yourself to us. If we learn that we have collected Personal Data from a child under the Age of Majority, we will delete that information as quickly as possible. If you believe that a child under the Age of Majority may have provided us with Personal Data, please contact us at privacy@nabucares.ai
Section 5 above (How We Use Personal Data) explains how we use your Personal Data. We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, but will depend on the type of Personal Data and the specific context in which we process it. However, the legal bases we typically rely on for each category of processing activity are set out below:
We may use your Personal Data for reasons not described in this Privacy Policy where permitted by law and where the reason is compatible with the purpose for which we collected it. If we need to use your Personal Data for an unrelated purpose, we will notify you and explain the applicable legal basis.
This Privacy Policy does not cover the practices of third parties that we do not own or control, or people that we do not manage. We are not responsible for the policies and practices of any third parties (such as Providers), and we do not control, operate, or endorse any information, products, or services that may be offered by third parties or accessible on or through the Services.
The Services may contain links to websites and other online services operated by third parties, such as Facebook, LinkedIn and Twitter. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not in themselves an endorsement of, nor a representation that we are affiliated with, any such third party.
We do not control websites or online services operated by third parties, and we are not responsible for their actions. You can learn about and control how these third parties use and share Personal Data about you, including with Nabu AI, by reviewing their privacy notices and exercising the privacy choices that the third party may offer.
We may review this policy from time to time. We recommend that you regularly check for changes and review this policy whenever you visit our website.
We will notify you of any minor changes by posting an updated version on our website or app, with an update to the “Effective Date” at the start of the policy. Where we intend to change our information handling practices (for example we intend to collect a new type of data or use data for a new purpose), we will also notify you via email of those changes.
If you do not agree with any aspect of the updated policy, you must immediately notify us and cease using our Services. If you use the Services after the effective date of any changes to the Privacy Policy, we will assume that you agree to all of the changes.
If you have questions, concerns, complaints, or would like to exercise any of your data protection rights, please contact us at:
Nabu AI Pty Ltd
Attn: Legal Department
L3, 360 Kent Street. Sydney, NSW, Australia, 2000
privacy@nabucares.ai
If you have any questions about this Privacy Policy, the data we hold on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.
If you have any complaints concerning the processing of your Personal Data, you can email us at privacy@nabucares.ai. Alternatively, you may contact the relevant data protection body in your jurisdiction:
If you are in the UK, contact the Information Commissioner’s Office, via email at icocasework@ico.org.uk.
If you are in the EU, you can contact the European Data Protection Supervisor online here or your nation’s data protection authority.
If you are in the US, contact your local state regulatory body.
If you are in Australia, contact the Office of the Australian Information Commissioner online here.