myHeart by GlobalHeart Privacy Notice

Effective Date: 20 July 2026
Version: 1.1

GlobalHeart Pte. Ltd. (“GlobalHeart”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal and health-related information.

 

Your doctor or clinic has referred you to use GlobalHeart to monitor your heart health.  This Privacy Notice explains how GlobalHeart collects, uses, stores, processes, and protects information when you use our wearable ECG devices, mobile applications, digital health platforms, and related services (collectively, the “Services”).

 

By using the Services, you acknowledge and consent to the practices described in this Privacy Notice.

 

1.        Information We Collect

GlobalHeart may collect and process the following categories of information:

A.        Personal Information

·         Name

·         Date of birth

·         Gender

·         Email address

·         Phone number

·         Account login information

 

B.        Health and Physiological Information

·         Real-time ECG readings

·         Heart rate waveform data and rhythm information

·         Monitoring duration and timestamps

·         Event markers and symptom inputs

·         AI-generated analytical indicators and summaries

 

C.       Device and Technical Information

GlobalHeart may collect technical information required for the operation of the Services, including:

·         Mobile device information

·         Operating system version

·         Application version

·         Bluetooth device identifiers, device identifiers and other technical identifiers required for pairing, authentication, communication and reconnection with authorized ECG monitoring devices.

·         IP addresses

·         Connectivity and synchronization status

D.     Physician and Clinical Workflow Information

Where applicable, physician review records, annotations, and sign-off information may be associated with generated reports.

E.     Bluetooth and Location Permission

Certain mobile operating systems may require Bluetooth and/or Location-related permissions to enable Bluetooth Low Energy (BLE) device discovery, pairing and automatic reconnection with compatible ECG monitoring devices.

myHeart requests and uses these permissions solely to discover, pair, connect and automatically reconnect authorized ECG monitoring devices while maintaining continuous ECG monitoring.

The App does not use these permissions to determine, retain or transmit the user's latitude, longitude, physical address, movement history or geographic location for navigation, advertising, marketing, profiling or analytics.

On platforms where Location permission is required solely to support Bluetooth Low Energy (BLE) scanning and reconnection, such permission is used only for that purpose and not to determine the user's geographic location.

2.     How We Use Your Information

GlobalHeart may use your information for purposes including:

·         Providing ECG monitoring and recording services

·         Generating health analytics and reports

·         Supporting physician review workflows

·         Improving system performance and service quality

·         Troubleshooting technical issues

·         Protecting platform security and preventing misuse

·         Meeting legal and regulatory obligations

·         Conducting internal service improvement, quality assurance and platform enhancement using anonymized or aggregated information where appropriate.

·         Supporting health management and wellness-related services

·         Providing physiological trend analysis and longitudinal monitoring

·         Supporting platform development and service improvements using anonymized or aggregated information where appropriate.

·         Providing ECG reports for professional review and sign-off by GlobalHeart-authorised physicians.

·         Making completed ECG reports available to users and, where applicable, to the referring doctor or clinic in connection with the Services.

 

3.            How the Reporting Process Works

Our Services are designed to support cardiac monitoring and health analytics workflows.

The general process is as follows:

  1. ECG and physiological data are collected through wearable devices and transmitted to the GlobalHeart mobile application.
  2. Data is securely processed and analyzed through GlobalHeart systems.
  3. Users may access generated health reports and analytical summaries through the mobile application after monitoring is completed.
  4. Where applicable, ECG reports are reviewed and signed off by GlobalHeart-authorised physicians through secured desktop-based clinical workflows before being made available to users and, where applicable, to the referring healthcare provider or clinic.

GlobalHeart’s Services are intended to support healthcare workflows and do not independently replace licensed medical professionals.

4.         AI-Assisted Analytics and Health Management Features

GlobalHeart may use AI-assisted technologies, analytics systems, and physiological data processing tools to support:

·         ECG and cardiac analytics

·         Health monitoring

·         Wellness-related insights

·         Longitudinal physiological trend analysis

·         Healthcare workflow support

·         Health management services and platform features

These technologies are intended to assist data analysis and healthcare-related workflows and are not intended to independently replace licensed medical professionals or constitute definitive medical diagnoses without appropriate clinical review.

5.         Data Storage and Security

GlobalHeart takes reasonable measures to protect your information against unauthorized access, loss, misuse, or disclosure.

Security measures may include:

·         Encrypted data transmission

·         Encrypted storage

·         Access controls

·         Authentication procedures

·         System monitoring and audit logging

Where practicable, GlobalHeart’s primary operational data processing infrastructure is hosted within Singapore-based cloud environments.

6.         Data Sharing and Disclosure

GlobalHeart may share information with:

·         Authorized healthcare professionals

·         Hospitals or healthcare institutions

·         Cloud infrastructure providers

·         Authorized service providers supporting platform operations

·         Regulatory authorities where required by law

GlobalHeart does not sell personal data or identifiable health information.

The App may access Location permission for Bluetooth device discovery and reconnection as described in Section 1(E). GlobalHeart does not use this permission to obtain, retain or transmit users’ latitude, longitude, movement history or geographic location for advertising, marketing, profiling or analytics.

Bluetooth device identifiers, device identifiers and other technical identifiers are processed solely to enable secure pairing, authentication, communication and reconnection between the App and authorized ECG monitoring devices. These identifiers may be processed by contracted cloud or technical service providers acting on GlobalHeart’s behalf, but are not shared with advertisers, data brokers or unrelated third parties.

7.         International Data Transfers

Where necessary, GlobalHeart may transfer information across jurisdictions in connection with platform operations, support services, or authorized collaborations.

GlobalHeart will take reasonable measures to ensure that transferred data receives protection standards comparable to applicable Singapore data protection requirements.

8.         Data Retention

GlobalHeart may retain personal and health-related information for operational, legal, regulatory, medical, security, and research purposes.

Older records may be archived under restricted-access environments.

Retention periods may vary depending on:

·         Healthcare operational requirements

·         Legal obligations

·         Regulatory expectations

·         System security and audit needs

When personal information is no longer required for the purposes for which it was collected, and no legal, medical-device, healthcare or regulatory retention obligation applies, GlobalHeart will delete, anonymize or securely dispose of the information.

9.         Your Rights

Subject to applicable laws and operational limitations, you may request:

·         Access to your personal information

·         Correction of inaccurate information

·         Clarification regarding how your information is used

·         Withdrawal of consent where applicable

·         Deletion of your myHeart account and associated personal data, subject to applicable medical, legal, regulatory and record-retention requirements.  Account deletion requests may be submitted through the account-deletion process published on GlobalHeart’s website.

GlobalHeart may require verification of identity before processing requests.

10.      Cookies

Our Services may use cookies or similar technologies, where applicable, to:

·         Maintain secure user sessions

·         Improve application functionality

·         Support operational performance

 

11.      Third-Party Services

Certain functions of the Services may rely on third-party providers such as cloud hosting, analytics, communication, or security providers.

These providers may process information on GlobalHeart’s behalf subject to appropriate contractual and security controls.

12.      Medical Disclaimer

GlobalHeart’s Services are intended to support cardiac monitoring and healthcare workflows.

The Services are not intended to replace professional medical advice, diagnosis, emergency care, or treatment.

If you believe you may be experiencing a medical emergency, please contact emergency medical services or a qualified healthcare professional immediately.

13.      Updates to This Privacy Notice

GlobalHeart may update this Privacy Notice periodically to reflect operational, legal, technological, or regulatory developments.

Updated versions may be published through our website or applications.

14.      Contact Us

If you have questions regarding this Privacy Notice or your personal information, please contact:

GlobalHeart Pte. Ltd.
Email: 
privacy@globalheart.com.sg
Website: 
www.globalheart.com.sg

This Privacy Notice is issued pursuant to the Personal Data Protection Act 2012 (Singapore) and the PDPC Advisory Guidelines for the Healthcare Sector (Revised September 2023). It does not constitute legal advice.

 


 

Appendix A – Third-Party Components and SDKs

The following table identifies third-party SDKs integrated into the App. Depending on the enabled features and application configuration, certain SDK capabilities may not be activated or used in the current version of the App.

Name of third-party’s SDK

Application Scenario

Types of collecting personal information

Privacy Policy Address

Bugly SDK

Used for capturing exceptions within applications and improving user experience

Network status information, device information

https://static.bugly.qq.com/bugly-sdk-privacy-statement.pdf

Alibaba SDK

Used for jumping between APP pages

Device Information

https://rule.1688.com/policy/privacy.html?spm=a260s.11051009.jb7hkfbc.10.496a55edojE5j4

QQ SDK

QQ share

Device Information

https://privacy.qq.com/

Wechat SDK

WeChat friends and WeChat social circle sharing function

Device Information

https://privacy.qq.com/

Alibaba Cloud SDK(Embedded Taobao SDK)

Used to implement message push and vendor push

Device Information

https://terms.aliyun.com/legal-agreement/terms/suit_bu1_ali_cloud/suit_bu1_ali_cloud201710161525_98396.html?spm=5176.12940851.7y9jhqsfz.2.188c5455ocC7aB

Alibaba Mobile Data Analysis Service

Used for user behavior analysis, refined operation of big data technology, improving product quality and experience

Running process informationDevice Information

https://help.aliyun.com/document_detail/30022.html

Alibaba Baichuan Components

Used to assist with Alibaba's message push function, allowing users to receive real-time electrocardiogram reports and various abnormal reminders during electrocardiogram monitoring processes

Running process informationDevice Information

https://jypt.07baby.com/Account/UserPrivacyPolicy

Message push

Mobile phones used for OPPO brand can receive real-time ECG reports and abnormal alerts related to ECG monitoring in both online and offline states

Running process informationInstalled APP Information

https://open.oppomobile.com/new/developmentDoc/info?id=10288

Xiaomi (third-party name: Xiaomi Technology Co., Ltd.)

Used to push messages to Xiaomi mobile phone users

Used to push messages to Xiaomi mobile phone users to collect personal information Type: device identifier (IMEI, MEID, and other device identifiers), application list, storage information

https://dev.mi.com/console/doc/detail?pId=860

HUAWEI Scan Kit

Scan the QR code page. Use the scan function to scan the host's QR code and connect it to the host through the QR code for ECG monitoring;

Text information, images, sensor information (acceleration sensors, lighting sensors), network information, device identifiers within the application, basic information of the application, hardware information of the device, operator information (operator name), system information (system settings, system properties, device model, operating system), WiFi information (WiFi status), information about your use of this application

https://developer.huawei.com/consumer/cn/doc/development/HMSCore-Guides/sdk-data-security-0000001050043971