Organization Name: AIRS Medical Inc.

Global Privacy Policy

AIRS Medical Inc., including its affiliates and subsidiaries (collectively, "AIRS Medical" and also referred to as "we", "us", and "our") respects your privacy and is committed to protecting it through our compliance with this policy. This privacy policy describes how the AIRS Medical collects, uses, and secures personal data, if necessary, with whom we share it. This policy has three parts: the general policy (Sections 1 to 12), Annex A for individuals in the European Economic Area and the United Kingdom, and Annex B for residents of the United States. If you are in the EEA or the UK, read Sections 1 to 12 together with Annex A; if you are a resident of the United States, together with Annex B. The Annex gives the rules that differ for your region. Your rights are in Section 6 (with A.4 and B.3) and our contact details in Section 11. Separate privacy policies apply in the Republic of Korea and Japan (see Section 10).

1. Scope, controller and the personal data we process

This policy explains how we process your personal data when you use our websites. This policy may change from time to time to reflect the changes to our privacy practices. We will notify you of any material changes by posting the new policy on this page and updating the "Effective Date" at the top. We encourage you to periodically review this page for the latest information on our privacy practices.

This privacy policy has been developed and is maintained in accordance with all applicable national and international privacy and data protection laws and regulations, specifically with the EU General Data Protection Regulation (GDPR)

1.1 Scope of this policy

This policy applies to personal data we collect through your use of this AIRS Medical(“Website”) website or through offline collection in connection with promotional engagement, partner management via post, phone, or email and in-person business meetings. This policy does not apply to the privacy practices of third-party websites or services. This policy applies to personal data we collect and process through: (a) the AIRS Medical website (airsmed.com) ("Website"); (b) our cloud-based medical imaging products and services, including SwiftMR and SwiftSight (collectively, "Products"); (c) offline interactions; (d) personal data we process in our capacity as a data processor on behalf of healthcare providers through our Products; and (e) personal data of job applicants and candidates that we collect through our careers pages, our recruitment platform provider, recruitment agencies and direct sourcing. Region-specific information for candidates, including the controller for the role, retention periods and transfer mechanisms, is set out in Annex A (EEA and UK), Annex B (United States) and the candidate privacy notice provided with the application form on our recruitment platform. We encourage you to read their privacy policies for information on how they handle your personal data.

The personal data of our employees during employment is covered by the Employee Privacy Notice provided with the employment contract.

1.2 Controller

AIRS Medical is the controller responsible for your personal data under applicable data protection laws. For processing activities specific to a particular region, the relevant local entity may act as the data controller as set out in the table below and in the applicable Annex or regional privacy policy. We have appointed a Chief Privacy Officer (CPO) who serves as our designated data protection contact under applicable regulations. The CPO is responsible for overseeing questions in relation to this privacy policy. For the European Economic Area, we have designated a separate Data Protection Officer (DPO) in accordance with GDPR Art. 37. Contact details for both are provided in the Contact Information section below. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact our CPO using information set out in the contact information section. For detailed contact information and jurisdiction-specific designations, please refer to the relevant specific section of this policy.

This table summarises our regional entities. For recruitment, the controller for the advertised role is identified in the candidate privacy notice provided with the application form; other group companies may receive the application for the purposes described there.

RegionResponsible AIRS Medical entityWhere the details are
Republic of KoreaAIRS Medical Inc. (Seoul)Privacy policy for the Republic of Korea (개인정보 처리방침)
European Economic Area and United KingdomAIRS Medical Europe GmbH (Munich); UK representative: Youtilix LtdAnnex A
United StatesAIRS Medical Inc.; AIRS Medical USA Inc. for recruitment in the United States and for sales and customer management in the AmericasAnnex B
JapanAIRS Medical Japan G.K. (Tokyo), through which AIRS Medical Inc. operates in JapanPrivacy Notice for Japan (English
日本語)
Patient data processed through our ProductsThe healthcare provider is the controller; AIRS Medical processes the data only on its documented instructions (in the United States as a business associate under HIPAA)Section 4; Annex B, Section B.5

1.3 Data minimisation

Unless otherwise instructed at the point of collection or where exceptions under applicable laws take precedence, AIRS Medical will make reasonable efforts to ensure that any use, disclosure, or request of personal data is limited to the minimum amount necessary to accomplish the intended purpose.

1.4 Personal data we collect

Providing personal information to us is entirely voluntary on your part. If you choose not to provide or allow data that is necessary for the service, we may not be able to deliver the services or certain aspects of it in their full capacity.

The personal data we collect depends on how you interact with us, the services you use, and the choices you make.

1.5 Information provided by you

You may directly give us your personal data when you complete online forms on our website or by corresponding with us by post, phone, email, in-person business meetings, or otherwise. This includes personal data you provide when you apply for our products or services, subscribe to our publications, request marketing materials to be sent to you, survey, give us feedback or contact us for general inquiries. The personal data we collect may include the following:

  • IDENTITY DATA includes [first name, last name, any previously known names, job title, your company, your country, or similar identifiers]
  • CONTACT DATA includes [email address, and telephone numbers]
  • MARKETING AND COMMUNICATIONS DATA includes [your preferences in receiving marketing from us]
  • RECRUITMENT DATA includes [CV/résumé and cover letter, education and employment history, qualifications and licences, language skills, work authorisation status, answers to application questions, interview notes and assessment results and, where you have agreed, talent-pool registration details]. We do not ask for special categories of data (such as health, religion or ethnic origin) or government-issued identification numbers at the application stage; please do not include them in your application, and we will delete them if they are provided.

Where required by applicable laws, we will obtain your prior consent before utilising your personal data for marketing purposes.

In connection with the payment of service fees for services you provide to us, we may collect additional information, including government-issued ID numbers, Tax ID numbers, bank account details, CVs for payment processing purposes.

1.6 Information collected automatically

As you navigate through and interact with our website, we may automatically collect Technical Data, Geolocation Data, and Usage Data. This covers details of your visits to our website, including traffic data, location information, logs, and other communication data, as well as the resources that you access and use on the website. We collect this data by using cookies, server log files, and other similar technologies. Please see our Cookie Policy for further details. The data we collect includes:

  • TECHNICAL DATA includes [Internet protocol (IP) address, internet connection, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device type and other technology on the devices you use to access this website]
  • GEOLOCATION DATA includes [geographical information based on your IP address, time zone, and, if enabled, device permissions that provide location data]
  • USAGE DATA includes [information about how you interact with and use our website, cookies and other tracking technologies]

1.7 Information collected from third-party sources

We may receive your personal data from third-party service providers, including social media platforms, advertising networks, analytics providers, if you access our website through an advertisement on their websites or applications. These providers may also provide us with aggregated data and analytics regarding your use of our website.

For recruitment, we may also receive personal data about you from recruitment agencies and search firms we engage, from professional networking platforms and job boards on which you have published a profile or applied, from referees you nominate and, only after a conditional offer and where permitted by local law, from background-check providers. Where we obtain your personal data from such a source, we will tell you where it came from in our first communication with you.

1.8 How we use your personal data

We use your personal data for the purposes we have described below in this privacy policy.

Manage our relationship with our customers and business partners. We will use your personal data:

  • to provide our products and services to you;
  • to verify your identity (e.g., if you already have access right to our Website or any agreement executed with us in place) and provide supports accordingly
  • to execute and perform agreement with our partners, clients, and suppliers;
  • to keep you informed about our products, services, and events and promotions. This includes sending newsletters, invitations to events (such as conferences, webinars) and other promotional updates to enhance your experience.
  • to respond to your inquiries and provide you with information when you request it or when we believe our products and services may be of interest to you or similar to those that you have already inquired about;
  • to conduct and facilitate surveys, feedback
  • to personalize your experience when interacting with AIRS Medical;
  • to provide customer support through various channels and analyze and improve our customer support

Manage recruitment. We will use your personal data:

  • to evaluate your application and your suitability for the role you applied for or for similar roles;
  • to communicate with you about your application and schedule interviews;
  • to verify the information you have provided, including reference checks and, where permitted by local law and only after a conditional offer, background checks;
  • to make and record hiring decisions and, if you are hired, to prepare your employment documentation;
  • to keep the records required by employment, equal-opportunity and record-keeping laws and to establish, exercise or defend legal claims; and
  • only where you have agreed, to keep your profile in our talent pool and contact you about future openings.

We have disabled scoring, ranking and automated progression features and do not use AI to evaluate candidates; every screening and selection decision is made by a member of our recruitment team.

Improve our processes and business operations. We will use your personal data:

  • to manage our network and information systems security;
  • to keep records related to our relationship with healthcare professionals;
  • to perform data analysis, auditing and research to help us deliver and improve our digital platforms, content and services; (including developing new products, services, channels);
  • to monitor and analyze trends, usage and activities in connection with our products and services to identify areas of interest and improve our products and services accordingly
  • to evaluate the effectiveness of our business through essential functions such as accounting, auditing, billing and financial reconciliation

Other necessary purposes. We will use your personal data:

  • to comply with applicable laws and regulations;
  • to fulfill legal obligations (including to comply with tasks mandated by law, such as disclosure to government, supervisory, tax, and sector-specific authorities, to respond to requests from competent public authorities);
  • to comply with and enforce contractual obligations and our policies and terms (including informing you of the changes to our terms and conditions; policies);
  • to exercise or defend AIRS Medical against potential, threatened or litigations;
  • to investigate and take action against illegal and harmful behaviour to protect interest of AIRS Medical
  • to adhere to applicable regulatory requirements and quality standards (including adverse event reporting to regulatory authorities; complaint and incident management by assessing and implementing corrective and preventive measures)

1.9 Legal basis of processing your personal data

The GDPR and other applicable privacy laws require us to have a legal basis for collecting and using your personal data. As such, we may rely on the following legal basis. AIRS Medical processes your personal data based on one or more of the following foundations to achieve the purposes described above.

  • CONSENT. We may process your personal data if you have given us explicit consent to use your personal data for a specific purpose, for example placing cookies on your device for “Statistics,” “Advertising,” and “Marketing” cookies as described in Section 9 certain situations where you share your sensitive data about yourself; electronic marketing communications; and in any other situation where personal data processing relies on your consent, such as contacting us for product free-trial or responding to your inquiries about our products and services. Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • PERFORMANCE OF A CONTRACT. We may process your personal data when we believe it is necessary to fulfill our contractual obligations to you, including providing our products and services; identifying and authenticating your access to our website, systems, and publications; responding to your inquiries; and personalizing your experience to meet your needs within the scope of the services we offer.
  • LEGITIMATE INTERESTS. Generally, the legitimate interest pursued by AIRS Medical in relation to the use of your personal data is the efficient performance or management of your use of our products and services, our business relationship with you, and the achievement of the specific purposes described herein. These purposes include, but not limited to, Selecting suitable business partners and verifying eligibility for products; Managing and securing our IT systems, communications, and networks; Preventing fraud and protecting the rights, privacy, safety, or property of AIRS Medical; Planning, improving, and analyzing our business activities, including trend analysis for product development; Ensuring quality control through training, feedback, and customer surveys; Handling your queries, providing customer service, and digitizing corporate records; Sending marketing materials (subject to your right to opt-out at any time). Before processing your personal data for our legitimate interests, we perform an assessment to balance our business needs against any potential impact on your rights and freedoms. We do not use your personal data for activities where our interests are overridden by the impact on you unless we have your consent or are otherwise required or permitted to by law.
  • LEGAL OBLIGATIONS. We may process your personal data when it is required to ensure compliance with our legal obligations. This includes, but is not limited to cooperation with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclosing your personal data as evidence in litigation in which we are involved, medical device safety reporting, tax and accounting regulations, and responding to requests from government authorities.
  • Special Categories of Personal Data. Health-related data processed through our Products is processed on behalf of the healthcare provider, which as Data Controller is responsible for establishing the applicable legal basis; we process it only on its documented instructions. Where we ourselves determine the purposes of processing special categories of personal data (for example, research using pseudonymised data), we rely on an applicable condition under data protection law, as described in Annex A. For further details, please refer to Annex A.

2. Sharing and disclosure of your personal data

  • AFFILIATES. We may share or disclose your personal data to our affiliates and subsidiaries given the global nature of operations. We strictly adhere to a 'need-to-know' principle, ensuring that access is restricted to authorized personnel who require the information to perform their specific duties.
  • BUSINESS PARTNERS. We may share or disclose your personal data to business partners, vicarious agents, or authorized distributors, or local representatives, particularly in markets where we do not have a direct presence or our market reach is deemed limited. In such cases, your personal data is shared only to the extent necessary to manage the business relationship with you and to achieve the purpose described in this Privacy Policy. We ensure that all such partners are selected based on their reputation and compliance standards. Furthermore, we maintain strict contractual safeguards (such as Data Processing Agreements) with these partners, obligating them to protect your personal data with the same level of integrity that we apply ourselves.
  • SERVICE PROVIDERS. We may share or disclose your personal data to authorized third-party service providers to perform functions on our behalf for effective business management or the fulfillment of the contract or at your request for the implementation of pre-contractual measures. The categories of the recipients include, but are not limited to, providers of content delivery and web hosting, analytics and marketing services (including social media platforms), payment processing and customer management systems, and, for recruitment, our recruitment platform provider (applicant tracking system), recruitment agencies and search firms, and reference- and background-check providers. These providers operate on our behalf and follow our instructions under Article 28 GDPR. Data processing agreements are in place with these providers, contractually binding them to keep your personal data confidential and to use it solely for specified purposes.
  • SUCCESSORS. We may share or disclose your personal data to entities such as potential acquirers of our business or brand, or a buyer or successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the company’s assets, whether as a going concern or as part of bankruptcy, liquidation, or a similar proceeding. In such cases, personal data held by AIRS Medical may be among the assets transferred, and the new owners may use your personal data in accordance with this privacy policy.
  • LEGAL PROCESS AND ENFORCEMENT. We may share or disclose your personal data if we are legally obligated or authorized to do so by law or legal process. (such as a court order or subpoena) This includes sharing information with law enforcement or government bodies to comply with valid legal requests. We also reserve the right to disclose personal data when essential to protect the rights, property, or safety of AIRS Medical, our customers or the public. This includes enforcing our terms of use and exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction
  • PROFESSIONAL ADVISORS. We may share or disclose your personal data to professional advisors such as auditors, accountants, lawyers, or insurers, where necessary in the course of the professional services that they render to us.
  • WITH CONSENT. In all other instances where applicable law requires specific authorization for data disclosure, we may share or disclose your personal data to other parties only after obtaining your explicit consent. Such disclosures will be conducted strictly to the extent permitted by law and in accordance with the specific purposes for which your consent was granted.

3. International data transfers

As a global organization, we may transfer your personal data across international borders to countries where data protection standards may differ from those in your home jurisdiction. Such transfers are made only to fulfill contractual and business obligations or to maintain our business relationship with you.

To support the delivery of our services, we utilize cloud infrastructure provided by Amazon Web Services (AWS), where data is generally processed and stored in the region where the service is delivered. In cases where data may be processed in a different jurisdiction, appropriate safeguards under applicable law are applied prior to any such transfer.

Recruitment data is hosted by our recruitment platform provider (Workable) in the United States and may also be processed in the United Kingdom and Greece, and may be accessed by the AIRS Medical group companies involved in recruiting in the Republic of Korea, the United States, Germany and Japan. The transfer mechanism that applies to your data (adequacy decisions, the EU-U.S. Data Privacy Framework, standard contractual clauses, equivalence recognition or your consent, as the case may be) is described in Annex A (EEA and UK), Annex B (United States) and the candidate privacy notice provided with the application form on our recruitment platform.

For transfers originating from other jurisdictions (e.g., South Korea, Japan), we comply with the applicable cross-border data transfer requirements of those jurisdictions, as further described in the privacy policies for Korea and Japan linked in Section 10.

You may obtain a copy of the safeguards used for international transfers by contacting privacy@airsmed.com.

4. Patient-related data processed on behalf of healthcare providers

For certain products and services, AIRS Medical may process patient-related data on behalf of healthcare providers (who act as the Data Controller). In this capacity, AIRS Medical acts as a Data Processor and processes such data strictly in accordance with the Controller’s documented instructions, applicable data processing agreements, and all relevant data protection laws.

The categories of patient-related data processed may include:

  • PATIENT IDENTIFIERS include [patient name, date of birth, medical record number, or other identifiers as contained in medical imaging metadata (e.g., DICOM tags)]
  • MEDICAL IMAGING DATA includes [diagnostic images (e.g., MRI scans), AI-generated analysis results, and associated diagnostic support reports]

Where technically feasible, we apply de-identification or pseudonymization techniques prior to transmission to our cloud-based processing environment. Where the nature of the service requires that certain patient identifiers (e.g., patient name) be transmitted to the cloud environment for clinical or diagnostic support purposes, such data is protected during transmission using robust encryption and advanced security measures designed to protect data integrity during transmission. Access is strictly limited to authorized personnel on a need-to-know basis, and all data is retained only for the period defined by the healthcare provider in accordance with applicable medical record retention laws.

For the processing described in this Section 4, AIRS Medical does not independently determine the purposes of processing patient-related data. All processing is performed under the direction and control of the healthcare provider (Data Controller), and we maintain data processing agreements that define the scope, duration, and nature of such processing in compliance with applicable data protection laws.

AIRS Medical's products are designed to assist healthcare professionals in their clinical decision-making and do not make autonomous diagnostic or treatment decisions. Our AI systems process medical imaging data (e.g., MRI scans) and associated metadata to generate enhanced images, reconstructed scans, or analytical outputs that are presented solely as supplementary information for the treating healthcare professional. All AI-generated outputs require review and validation by a qualified healthcare professional, who retains full authority to accept, modify, or disregard any AI output, before any clinical action is taken. AIRS Medical does not engage in solely automated decision-making as defined under Article 22 of the GDPR. For further information on how our AI systems process data and your related rights, please refer to Annex A (Section A.6).

5. Data retention and deletion

To the extent permitted by applicable law, we retain the personal information we obtain about you as long as:

  • it is needed for the purposes for which it was originally collected, in accordance with the provisions of this Privacy Policy; or
  • we have another lawful basis for retention—such as complying with legal obligations (including retention mandates under tax, commercial, or other applicable laws)—beyond the period necessary to serve the original purpose.

Unless otherwise indicated at the time of collection (e.g., within a specific form completed by you) or unless we have obtained your explicit consent for a different duration, we will process and retain your personal data in accordance with the standards stated above.

Recruitment data is retained for the period stated in Annex A (EEA and UK), Annex B (United States) or the candidate privacy notice provided with the application form (between one month and four years after the recruitment decision, depending on local law) or, where you have agreed to join our talent pool, for the period stated in that consent. Data of successful candidates becomes part of the employee file.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process personal data, and whether we can achieve those purposes through other means.

We retain cookie data in accordance with retention periods stated in the Cookie Policy.

You have the right to request deletion of your personal data at any time, subject to certain exceptions where we are required to maintain the data to comply with our legal obligations or to establish, exercise, or defend legal claims (see Your Legal Rights below).

6. Your legal rights

To the extent provided by the laws of your jurisdiction, you are entitled to certain rights regarding your personal data. Please note that these rights are not absolute and may vary depending on where you reside; as such, they may be subject to specific exceptions under applicable law.

  • Right to Be Informed. Be informed about the collection and use of your personal data
  • Right of Access. Have access to personal data about you. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Right to Erasure (Right to Be Forgotten). Have data about you deleted. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request. Especially where we act as a Data Processor for healthcare providers, any erasure request must be directed to the relevant Data Controller (e.g., your hospital or physician), as we are contractually and legally bound to retain data according to their instructions and applicable medical record retention laws. We will notify you of such reasons, if applicable, at the time of your request
  • Right to Rectification. Have information about you corrected. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

Right to Restrict Processing. You may request restriction of processing in the circumstances set out in Article 18 GDPR. Right to Object. You may object to processing under Article 21 GDPR, including where we rely on a legitimate interest as the legal basis for that particular use of your data; if you object to processing for direct marketing, we will stop using your data for that purpose. To ensure your request is handled correctly, please note the following:

  • In cases where we act as a Data Processor, we will facilitate your request through the relevant Data Controller(e.g., your hospital or physician). Please note that, if processing is restricted, it may render the provision of certain services or diagnostic functions impossible.
  • In cases where we act as a Data Controller, we will cease the processing of your data unless we can demonstrate compelling legitimate grounds for further processing which override the data subject’s interest in objecting. If the data processing is based on consent in accordance with applicable laws, you can revoke your consent at any time with effect for the future without affecting the legality of the previous processing.
  • Right to Data Portability. Data portability to allow you to obtain and reuse your personal data for your own purposes, across different services. This allows you to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability. We will provide you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Right to Withdraw Consent. Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. To ensure clarity regarding the impact of withdrawal, please note:

  • In cases where we act as a Data Processor: If you wish to withdraw consent for data processed through our services provided to a healthcare provider, you must contact the Data Controller (e.g., your hospital or physician) directly. As a processor, we act upon the Controller’s instructions and will execute the erasure or cessation of processing once we receive a formal request from them.
  • When we act as a Data Controller: Upon receiving your withdrawal of consent, we will erase the relevant personal data, provided that its continued processing is no longer necessary and there is no other overriding legitimate interest or legal obligation for us to maintain it.
  • Legal and Service Impact: The withdrawal of consent does not affect the lawfulness of any processing carried out before the withdrawal. Please be aware that if you withdraw your consent, we may no longer be able to provide certain services to you. In such cases, we will inform you of the specific impact at the time of your withdrawal.

For your protection, and to protect the privacy of others, we may need to verify your identity before completing what you have asked us to do.

6.1 Exceptions to the right to erasure

Please be aware that there may be specific situations where AIRS Medical is legally entitled or required to deny or restrict your privacy rights. In particular, we may decline a request to erase your personal data if the processing is necessary for one of the following reasons:

  • to comply with legal obligations under applicable laws (including those of EU Member States, where applicable)
  • to establish, exercise or defense of legal claims
  • to perform a public interest task or exercise official authority
  • for public health reasons
  • for archival, research or statistical purposes
  • to exercise our right to freedom of expression or information

6.2 Data subject access requests

Once we have verified your identity, we respond to and resolve all Subject Access Requests we receive from you regarding your personal data within one month of receipt of the request as outlined under the GDPR and other applicable laws. Occasionally, it could take us longer than a month if your request is particularly complex or you have made a number of requests. In such cases, we will notify you within the first month and provide an estimated timeline for completion.

Under the GDPR, any extension is limited to a further two months, and we will notify you of the extension and its reasons within one month of receiving your request.

In principle, you will not have to pay a fee to access your personal data or to exercise any of the other rights. However, as permitted by applicable law, we may charge a reasonable fee or refuse to act on your request if it is manifestly unfounded, repetitive, or excessive. (see below) To submit a data subject access request, contact privacy@airsmed.com or use our online request form. Please note that where AIRS Medical acts as a Data Processor on behalf of a healthcare provider (the Data Controller), we may be contractually required to redirect your request to the relevant provider. We will cooperate with and support the healthcare provider to ensure your request is addressed in accordance with applicable law.

6.3 Children’s personal data

The website of AIRS Medical is not directed toward, nor intended for use by, children. We do not knowingly collect or process personal data from individuals under the minimum age required for consent in their respective jurisdictions. (e.g., 13 years of age in the U.S., 14 years of age in South Korea, or 13 in the UK, between 13 and 16 in the EEA").

If you are under the applicable minimum age in your jurisdiction, please do not use this website, register, or participate in any of the interactive features of this website, or provide any personal data to us, including your name, postal address, telephone number, or email address.

If you believe we might have inadvertently collected any personal data from a child under the applicable legal age for consent without verified parental consent, please contact us using the contact information below. Upon discovery or notification, we will take steps to delete such data from our systems.

7. Data security and data breaches

We implement a comprehensive range of organizational, technical, and physical security measures designed to protect your personal data against unauthorized access, loss, or alteration, disclosure. We are committed to maintaining the integrity and confidentiality of your information through robust management practices, including:

7.1 Data breaches

AIRS Medical endeavors to protect your personal data by maintaining administrative, technical, physical security measures. However, in the unfortunate and rare event of a data breach that poses a risk to you, we will notify the relevant parties in accordance with applicable data protection laws and our contractual obligations. Where we act as a data processor, we will notify the data controller without undue delay upon becoming aware of a breach.

This will give you an opportunity to try and take steps to protect your positions, for example, enable you to change passwords and inform your banks that you may be at risk of identity fraud.

8. De-identified and aggregated data

To the extent permitted by law, we may also utilize de-identified or aggregated data that no longer identifies an individual to improve our offerings. Personal data obtained through various channels may be aggregated to calculate the percentage of users accessing a specific website feature in order to analyze general trends in how users are interacting with our website to help improve the website and our service offering. This approach enables us to provide a better and more personalized service. By using this data, we can estimate audience size and usage patterns, store information about your preferences, customize our website according to your interests, speed up searches, and recognize you when you return to our website.

9. Cookies and similar technologies

Cookies are small text files that are stored by the Internet browser on your device. A cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is called up again. We use cookies to ensure that our website functions properly and we also use cookies to analyze your interaction with our Website. When you access our Website, we inform you about our use of cookies.

Some features of our website cannot be offered without the use of cookies (“Technical” or “Functional” cookies). These cookies are strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by you, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.

For cookies that are not technically necessary (“Statistics,” “Advertising,” and “Marketing” cookies), we require your consent to process the personal data associated with them. These cookies may be used in aggregate to help us understand how our website is being used or to help us customize our website for you. You may adjust or opt out of cookie preferences by clicking on ‘Manage Consent’ at the left bottom of the website. Therein, a link to our privacy policy is also provided for additional context.

  • BROWSER COOKIES. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting, you may be unable to access certain parts of our website. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our website.
  • THIRD-PARTY COOKIES. We also use third-party cookies on our website. The legal basis for the use of cookies and the subsequent data processing is your consent in accordance with Article 6(1)(a) GDPR. The following cookie-based tools are used: Elementor, WordPress, WPForms, Google Analytics (and other various services), Wordfence, CloudFlare, Complianz, Hotjar, Meta Pixel, LinkedIn Insight Tag For further details, please see our Cookie Policy.
  • WEB BEACONS. Pages of our website may contain small electronic files known as web beacons (also referred to as tracking pixels, such as Meta Pixel or LinkedIn insight Tag) that permit AIRS Medical to count users who have visited those pages for other related website statistics.

10. Regional annexes and privacy policies for Korea and Japan

Annex A (European Economic Area and United Kingdom) and Annex B (United States) form part of this policy. Separate privacy policies apply in the Republic of Korea and Japan; they are linked below.

11. Contact information, Data Protection Officer, UK representative and supervisory authorities

If you have any questions about this privacy policy, or if you would like us to update information we have about you or your preferences, please fill out the Contact Us form or directly reach out to us at:

ContactDetails
AttnChief Privacy Officer
Email Addressprivacy@airsmed.com
Postal AddressAIRS Medical Inc., 13-14 Floor, Keungil Tower, 223, Teheran-ro, Gangnam-gu, Seoul, 06142, Republic of Korea

For questions or requests relating to a job application or our talent pool, you may also contact our Global HR team at ghr@airsmed.com (Korea domestic recruitment: hr@airsmed.com). Requests are handled together with the Chief Privacy Officer and, for the EEA and UK, the Data Protection Officer.

11.1 Data Protection Officer (DPO) for the EEA and the United Kingdom

In accordance with Article 37 of the EU General Data Protection Regulation (GDPR), We have designated a Data Protection Officer (DPO) for the European Economic Area. The DPO is responsible for overseeing compliance with applicable data protection laws within the EEA, advising on data protection obligations, and serving as a contact point for data subjects and supervisory authorities on all matters related to the processing of personal data.

If you are located in the European Economic Area and have questions or concerns regarding the processing of your personal data, or wish to exercise your rights under the GDPR, you may contact our DPO directly.

ContactDetails
AttnData Protection Officer
Email Addressjan.boennighaus@airsmed.com
Postal AddressAIRS Medical Europe GmbH, Oskar-von-Miller-Ring 20, 80333 Munich, Germany

UK AIRS Medical has designated a Data Protection Officer (DPO) for the processing of personal data of individuals in the United Kingdom. Our DPO can be contacted using the details above.

11.2 UK Our appointed UK representative

UK In accordance with Article 27 of the UK GDPR, AIRS Medical has appointed the following representative in the United Kingdom:

UK If you have any data access requests, further questions, or wish to lodge a formal complaint regarding our data processing activities, please contact our UK-based representative below:

UK Representative: Youtilix Ltd (registered in England and Wales, company number 15782133).

  • UK Email Address: DPO@youtilix.com
  • UK Postal Address: 167-169 Great Portland Street, London, England, W1W 5PF

11.3 Complaints to supervisory authorities

If you are unhappy about how we have handled your personal data you can make a complaint to our CPO who will investigate the matter and report back to you. We would appreciate the chance to deal with your concerns before approaching the competent authorities so please contact us in the first instance. You may complain to a supervisory authority at any time; you do not need to contact us first.

If you are still not satisfied after our response or believe we are not using your personal data in line with the law, you have the right to make complaints to the supervisory authorities or file an action directly in court against a company.

  • [UK] You can complain to the Information Commissioner’s Office (ICO), the UK regulator for data protection issues (www.ico.org.uk).
  • [EU] You can complain to a Data Protection Authority (DPA) against a company. DPAs are the national or regional public authorities who supervise the application of data protection laws and have the power to issue fines or other penalties against companies.
  • [Other Jurisdictions]: For users in other regions, you may contact the relevant national data protection authority in your jurisdiction (e.g., the Personal Information Protection Commission (PIPC) in South Korea).

11.4 Supervisory authorities

EEA The competent data protection authority for AIRS Medical Europe GmbH is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA). Data subjects in the EEA have the right to lodge a complaint with this authority or with the supervisory authority in their country of residence.

ContactDetails
AuthorityBayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Postal AddressPromenade 18, 91522 Ansbach, Germany
Telephone+49 (0) 981 180093-0
Emailpoststelle@lda.bayern.de
Websitehttps://www.lda.bayern.de

UK The competent data protection authority for individuals in the United Kingdom is:

UK Information Commissioner's Office (ICO)

  • UK Address : Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • UK Telephone: 0303 123 1113
  • UK Website: https://ico.org.uk

UK You have the right to lodge a complaint with the ICO if you believe that your personal data has been processed in a manner that does not comply with the UK GDPR.

12. Changes to this privacy policy

We keep our privacy policy under regular review to make sure it is up to date and accurate. The date of the last update can be found at the beginning of this privacy policy. In the event of material changes, we will notify you by email or through a prominent notice on our website at least 30 days prior to the changes taking effect. We recommend that you visit this page regularly to check for any updates that may have been made.

DateVersionDescription of Change(s)Reason for Change(s)Change(s) Made by
September 14, 20262.1Consolidated policy: Annex A (EEA and UK) and Annex B (United States) added; regional controller table (1.2); candidate privacy notice and consent form provided with the application formStructure decision 2026-09-09 — three published documents (Global, Korea, Japan)Information Security Team

Earlier versions of this policy and of the former regional notices are available on request.

Annex A. European Economic Area and United Kingdom

This section provides additional information for individuals located in the European Economic Area (EEA), in accordance with the EU General Data Protection Regulation (GDPR). UK This section provides additional information for individuals located in the United Kingdom, in accordance with the UK GDPR and Data Protection Act 2018 (DPA 2018), Data (Use and Access) Act 2025. This Annex forms part of this Global Privacy Policy; Sections 1 to 12 explain the categories of data we collect, the recipients of your data and your general privacy rights.

A.1. Data controller and legal basis for processing

UK For individuals in the United Kingdom, references in this Annex to the GDPR and to its Articles are to the UK GDPR and the corresponding Articles, read together with the Data Protection Act 2018. Sentences marked "UK" apply to the United Kingdom only, sentences marked "EEA" apply to the European Economic Area only, and all other sentences apply to both.

A.1.1 Data controller

For processing activities related to the EEA and the United Kingdom, the data controller is:

  • AIRS Medical Europe GmbH
  • Postal Address: Oskar-von-Miller-Ring 20, 80333 Munich, Germany

AIRS Medical Europe GmbH is a subsidiary of AIRS Medical Inc. and is responsible for determining the purposes and means of processing personal data of individuals in the EEA and the United Kingdom.

For inquiries regarding personal data processing that fall outside the scope of the EEA and UK operations, please refer to the global contact information provided in Section 11 of this policy.

A.1.2 Legal basis for processing personal data

AIRS Medical collects and processes personal data for the following reasons.

(a) Job applicants and candidates. For roles advertised by our European entity, the controller is AIRS Medical Europe GmbH. We process your application in order to take steps at your request prior to entering into an employment contract (Article 6(1)(b)). We rely on our legitimate interests (Article 6(1)(f)), subject to a balancing assessment, to share applications within the AIRS Medical group for assessment and support, to contact candidates whose details we obtained from recruitment agencies or from professional profiles you have made public, and to retain records for the period in which legal claims may be brought. We keep your profile in our talent pool only with your consent (Article 6(1)(a)), which you may withdraw at any time. Where we did not obtain your personal data from you directly, we will provide the information required by Article 14, including its source, within one month of obtaining it or, if earlier, at our first communication with you or at the first disclosure to another recipient (Article 14). Full details are set out in the candidate privacy notice provided with the application form on our recruitment platform.

For recruitment by AIRS Medical Europe GmbH, we also process application data under section 26(1) of the German Federal Data Protection Act (BDSG) where necessary to decide on the establishment of an employment relationship.

(b) Customers (e.g., healthcare institutions). For processing the personal data of healthcare professionals and administrative staff at the healthcare institutions we serve, we rely on:

  • Performance of a Contract (Article 6(1)(b)): To set up user accounts, deliver our software services, provide technical support, and manage billing and invoicing.
  • Legitimate Interest (Article 6(1)(f)): To manage our client relationships, improve the user experience of our products, conduct security monitoring, and send service updates.
  • Consent (Article 6(1)(a)): To send promotional materials or newsletters, where explicit consent is required by applicable electronic marketing laws.
  • UK Consent (UK GDPR Article 6(1)(a)): To send promotional materials or newsletters, where explicit consent is required under the Privacy and Electronic Communications Regulations 2003 (PECR).

Article 6(1)(b) applies where you are personally a party to the contract. For contact and account information of personnel acting for a healthcare institution or other organisation, we rely on Article 6(1)(f), subject to a balancing assessment, for our legitimate interest in providing services to and managing our relationship with that organisation.

(c) Business partners and vendors. For processing the personal data of our suppliers, consultants, and business partners, we rely on:

  • Performance of a Contract (Article 6(1)(b)): To manage procurement, negotiate and execute agreements, and process payments.
  • Legal Obligation (Article 6(1)(c)): To maintain accurate corporate accounting, audit, and tax records.
  • Legitimate Interest (Article 6(1)(f)): To conduct due diligence, assess vendor performance, and manage our general business operations and communications.

(d) Health data. Health data constitutes a special category of personal data under Article 9 of the GDPR. AIRS Medical processes health data in the course of the usage of AI-powered solutions as follows:

Where AIRS Medical acts as a Data Processor: In most cases, AIRS Medical processes patient data on behalf of healthcare institutions under a Data Processing Agreement. The healthcare institution, as the Data Controller, is responsible for establishing the appropriate legal basis for the initial collection and processing of patient data; we process patient data only on its documented instructions.

Where AIRS Medical acts as a Data Controller: For activities where AIRS Medical determines the purposes and means of processing (e.g., product improvement, algorithm training using pseudonymised data), the applicable legal bases may include:

  • Explicit consent of the data subject (Article 6(1)(a) together with Article 9(2)(a)); or
  • Legitimate interest (Article 6(1)(f)) & Scientific research purposes (Article 9(2)(j)) : We may rely on our legitimate interest to improve and develop our medical AI software (Article 6(1)(f)), paired with the condition that processing is necessary for scientific research purposes (Article 9(2)(j)).This processing is subject to a legitimate interest assessment (balancing test) and strict technical safeguards, including data minimisation and pseudonymisation.
  • UK Legitimate interest (UK GDPR Article 6(1)(f)) paired with scientific research purposes (UK GDPR Article 9(2)(j), read together with Schedule 1, Part 1, Paragraph 4 of the DPA 2018). This processing is subject to appropriate safeguards, including data minimisation and pseudonymisation.

EEA We rely on Article 9(2)(j) only where the processing is authorised by applicable Union or Member State law and the Article 89 safeguards are met; the applicable statutory basis is identified in the relevant research notice.

Information identified as required in the relevant application, onboarding or service form is necessary to assess your application, enter into or perform the relevant contract, or meet the legal requirement identified on that form. Without it, we may be unable to proceed with the relevant application, employment or service. Talent-pool registration and consent-based marketing are optional.

A.2. International data transfers

As the nature of our business aims to operate globally, your personal data may be transferred to, stored, and processed in countries outside the European Economic Area (EEA) or the United Kingdom, including to our headquarters in the Republic of Korea and other subsidiaries of AIRS Medical, and to our trusted third-party service providers (e.g., AWS).

EEA When we transfer your personal data outside the EEA, we ensure that a similar degree of protection is afforded to it by ensuring at least one of the following legal safeguards is implemented in accordance with GDPR requirements:

UK When we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place in accordance with the UK GDPR:

  • EEA Adequacy Decisions: We may transfer personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission. Transfers to our headquarters in the Republic of Korea are based on the European Commission’s Adequacy Decision for the Republic of Korea as of December 2021.
  • EEA Standard Contractual Clauses (SCCs): Where we transfer data to countries that do not have an adequacy decision, we rely on the approved Standard Contractual Clauses adopted by the European Commission.
  • EEA EU-US Data Privacy Framework: For certain transfers to the United States, we may rely on service providers who are certified under the EU-US Data Privacy Framework.
  • UK UK Adequacy Regulations: We may transfer personal data to countries that the UK Secretary of State has determined provide an adequate level of protection for personal data. Transfers to the European Economic Area (EEA) are covered by UK adequacy regulations. Transfers to our headquarters in the Republic of Korea are based on the UK Secretary of State’s Adequacy Decision for the Republic of Korea as of December 2022.
  • UK International Data Transfer Agreement (IDTA) or UK Addendum to EU SCCs: Where we transfer data to countries that are not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement (IDTA) approved by the ICO, or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.
  • UK UK Extension to the EU-US Data Privacy Framework: For certain transfers to the United States, we may rely on service providers who are certified under the UK Extension to the EU-US Data Privacy Framework.

UK A Transfer Risk Assessment (“TRA”, Data Protection Test under Data (Use and Access) Act) is conducted for transfers relying on the IDTA or UK Addendum to ensure that the standard of protection for your personal data is not materially lower after transfer.

EEA Health data processed through our products for European customers is primarily processed and stored within the EEA. Where strictly necessary for product development or technical support, health data may be transferred to our headquarters under strict technical measures, including pseudonymisation and encryption, to ensure the security of your data.

UK Health data processed through our products for UK customers is primarily processed and stored within the UK or EEA. Where strictly necessary for product development or technical support, health data may be transferred to our headquarters under strict technical measures, including pseudonymisation and encryption.

Destination countryPurposesLegal safeguard (EEA)Legal safeguard (UK)
Republic of Korea (HQ)Group-internal administration, product development, group-wide recruitment reviewAdequacy DecisionUK Adequacy Regulations
JapanGroup-internal administration, recruitment supportAdequacy DecisionUK Adequacy Regulations
GermanyGroup-internal administration, recruitment supportController's own country (Germany) — no third-country transfer from the EEAUK Adequacy Regulations
United StatesGroup-internal administration, customer support, SaaS service providers (CRM tool), recruitment support by AIRS Medical USA Inc.AIRS Medical USA Inc. (controller-to-controller): Standard Contractual Clauses (Module 1) with a transfer impact assessment; service providers acting as processors: Standard Contractual Clauses (Module 2) or an applicable EU-U.S. Data Privacy Framework certificationAIRS Medical USA Inc. (controller-to-controller): UK Addendum to the EU SCCs (Module 1) or IDTA, with a transfer risk assessment; service providers acting as processors: UK Addendum to the EU SCCs (Module 2) or IDTA, or the UK Extension to the EU-U.S. Data Privacy Framework where available
United StatesHosting and support of our recruitment platform (Workable Inc. and its sub-processors, including AWS, Google Cloud and MongoDB)EU-U.S. Data Privacy Framework certification of Workable Inc., which covers applicant data; the EU Standard Contractual Clauses (Module 2) in Workable's Data Processing Agreement apply as a fallbackUK Extension to the EU-U.S. Data Privacy Framework (Workable Inc.), which covers applicant data; the UK Addendum to the EU SCCs in Workable's Data Processing Agreement applies as a fallback
United KingdomContracting and support of our recruitment platform (Workable Software Limited)European Commission adequacy decision for the United Kingdom (valid until 27 December 2031)Domestic processing in the United Kingdom — not a restricted transfer
GreeceSupport of our recruitment platform (Workable Software Single Member P.C.)EEA member state — no third-country transferUK Adequacy Regulations (EEA)

UK Our recruitment platform provider, Workable Software Limited, is established in the United Kingdom; its processing of applicant data in the United Kingdom does not involve a restricted transfer.

You may request a copy of the contractual safeguards applicable to transfers of your personal data by contacting our DPO using the details in Section 11 of this policy; necessary redactions may be made to protect confidential information.

A.3. Retention period

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:

  • EEA Candidate data: six months after we communicate the recruitment decision, to cover the period in which claims under the German General Equal Treatment Act (AGG) may be brought and pursued; talent-pool data: up to three years from your consent or until you withdraw it, whichever is earlier; data of successful candidates is transferred to the employee file and retained as employment data.
  • UK Candidate data: six months after we communicate the recruitment decision (covering the period in which employment-tribunal claims may be brought); talent-pool data: up to three years from your consent or until you withdraw it, whichever is earlier; data of successful candidates is transferred to the employee file.
  • EEA Customer and business partner data: For the duration of the contractual relationship. Plus, any applicable statutory limitation period under the relevant Member State laws.
  • UK Customer and business partner data: For the duration of the contractual relationship, plus any applicable statutory limitation period under UK law.
  • Health data processed as a Data Processor: In accordance with the retention schedule defined by the relevant healthcare institution (Data Controller). AIRS Medical does not independently determine retention periods for data processed on behalf of its customers. (Healthcare Institutions)
  • Health data processed as a Data Controller (e.g., for product improvement or research): Retained in pseudonymised or anonymised form only for as long as necessary to achieve the stated research or development purpose, subject to periodic review.
  • Marketing and consent records: Until consent is withdrawn, or as otherwise required to demonstrate compliance.

When personal data is no longer required, it is securely deleted or anonymised in accordance with our internal data retention and disposal procedures.

A.4. Your rights under the GDPR and the UK GDPR

In addition to the rights described in Section 6 of this policy, you have the following rights under the GDPR:

(a) Rights in relation to AI-assisted processing (Article 22 GDPR) As described in Section A.6 (AI-assisted processing) below, our products do not engage in solely automated decision-making. Should you believe that a decision affecting you has been made without meaningful human involvement, you have the right to request human intervention, express your point of view, and contest the decision. Because clinical decisions are ultimately made by your healthcare provider (the Data Controller), requests regarding specific medical outcomes will be directed to the relevant healthcare institution.

UK For the United Kingdom, these rights arise under UK GDPR Articles 22A–22D, as amended by the Data (Use and Access) Act 2025.

EEA (b) Right to lodge a complaint You may lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

UK (b) Right to make a data protection complaint If you believe that we have infringed data protection legislation in the way we have handled your personal data, you have the right to lodge a complaint directly with us. You may submit your complaint to our Data Protection Officer (DPO) or our UK Representative using the contact details in Sections 11.1 and 11.2. We will acknowledge your complaint within 30 days of receipt, investigate and inform you of the outcome without undue delay, and keep you appropriately informed of progress.

UK (c) Right to lodge a complaint If you are not satisfied with our response to your complaint, or at any time, you may lodge a complaint with the Information Commissioner's Office (ICO).

A.4.1 How to exercise your rights

If you wish to exercise any of the above rights, or if you have questions about how our AI systems process your data, you may contact our Data Protection Officer using the details in Section 11.1.

Job applicants and candidates may also contact our Global HR team at ghr@airsmed.com; requests concerning recruitment are handled together with the Data Protection Officer. Please write from the email address you used to apply so that we can verify your identity. We will respond within one month.

UK You may also lodge a complaint with the Information Commissioner's Office at any time.

If your data has been provided to AIRS Medical by a healthcare institution, we may direct your request to the relevant Data Controller, as they are responsible for managing your rights in respect of the data they have collected.

We will respond to your request without undue delay and in any event within one (1) month of receipt, in accordance with Article 12 of the GDPR.

A.5. Data breach notification

Where AIRS Medical acts as a Data Controller: In the event of a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, which may include, for example, unauthorised access to medical imaging data or health records, we will also notify the affected data subjects without undue delay, providing clear information about the nature of the breach, the likely consequences, and the measures taken or proposed to address it.

UK For the United Kingdom, the competent supervisory authority is the Information Commissioner's Office (ICO).

Where AIRS Medical acts as a Data Processor: We will notify the relevant data controller without undue delay upon becoming aware of a personal data breach, providing sufficient information to enable the controller to fulfil its notification obligations under Articles 33 and 34 of the GDPR.

In all cases, we document the facts of any personal data breach, its effects, and the remedial actions taken, in accordance with Article 33(5) of the GDPR.

A.6. AI-assisted processing and the EU Artificial Intelligence Act

A.6.1 Human oversight and the role of healthcare professionals

AIRS Medical does not engage in solely automated decision-making as defined under Article 22 of the GDPR. All AI-generated outputs are designed to be reviewed and validated by a qualified healthcare professional before any clinical action is taken. This means:

UK For the United Kingdom, the reference to Article 22 in this subsection is to Articles 22A–22D of the UK GDPR, including the meaning of a significant decision based solely on automated processing in Article 22A.

A.6.2 Data protection impact assessments

Where our AI-powered products process health data or other special categories of personal data in a manner that is likely to result in a high risk to the rights and freedoms of individuals, we conduct Data Protection Impact Assessments (DPIAs) in accordance with Article 35 of the GDPR. Our DPIAs evaluate the necessity and proportionality of the processing, assess risks to data subjects, and identify measures to mitigate those risks. We review and update our DPIAs on an ongoing basis to reflect changes in our processing activities or risk profile.

A.6.3 Recruitment

Our recruitment platform offers optional AI-assisted features such as CV parsing and match scoring. We have disabled scoring, ranking and automated progression features and do not use AI to evaluate candidates; every screening and selection decision is made by a member of our recruitment team.

A.6.4 Compliance with the EU Artificial Intelligence Act

EEA The EU Artificial Intelligence Act applies in the European Economic Area; it does not apply in the United Kingdom.

EEA Your rights under the AI Act. You may complain to the relevant market surveillance authority about a suspected infringement of the AI Act under Article 85. Where Article 86 applies to a decision based on a high-risk AI system listed in Annex III, you may obtain a clear and meaningful explanation from the deployer. You may also contact us with questions about our products. For inquiries, please contact us at: privacy@airsmed.com or jan.boennighaus@airsmed.com (DPO)

Annex B. United States (CCPA/CPRA and other state privacy laws)

For residents of U.S. states with enhanced privacy rights, this section offers additional details on our data practices beyond our general Privacy Notice, covering the collection, use, and disclosure of your personal information in accordance with applicable state privacy laws, including but not limited to the California Consumer Privacy Act (CCPA/CPRA) and other state laws that may grant you additional rights regarding your personal information

B.1. Personal information we collect, use and disclose

We are also committed to the highest standards of protection for protected health data (PHI). In our role as a Business Associate to healthcare providers, AIRS Medical may process PHI in strict accordance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its implementing regulations, including the Privacy, Security, and Breach Notification Rules (collectively, the “HIPAA Standards”).

While we maintain rigorous security standards for all data, personal information that constitutes Protected Health Information (PHI) is governed by HIPAA. In accordance with statutory exemptions under various state privacy laws, PHI may be exempt from particular state consumer privacy laws; HIPAA does not displace applicable state laws that provide greater privacy protections. We evaluate both state and federal laws before disclosing or processing PHI without prior authorization. In cases where state laws provide a higher level of privacy or more extensive rights than HIPAA, we adhere to those stricter state-level standards. For a detailed explanation of our PHI practices, please refer to the [HIPAA Compliance] section below.

B.1.1 Categories, sources, purposes and disclosures (past 12 months)

The following table outlines the categories of personal information we have collected and processed and disclosed with third parties for business operations over the past 12 months, based on your interactions with our services. It also specifies any data 'sold' to or 'shared' with third parties for targeted advertising, as those terms are defined under the CCPA, during the same period. Please note that we never knowingly sell or share the personal information of users under the age of 16.

Category of personal informationSourcesPurposes for collection, use and disclosureRecipients for business purposes, including service providers and contractorsThird parties to whom we may “sell” or “share”
Identifiers (personal information) (e.g.,) Name, telephone number, postal address, online identifier, IP address, email addressDirectly from you
Cookies on the Channels
Strategic Business Partner
To support your experience with our products and services and manage professional relationship with us, as outlined in our Privacy Policy
To improve our business operation
To comply with applicable laws and regulations
To fulfill legal obligations
AIRS Medical Affiliates
Strategic Business Partner
Payment processors
Database management providers
Analytics and Optimization Providers
Authorized distributors
Professional advisors
Governmental and law enforcement officials
Marketing, Advertising, and Social Media Networks
Sensitive Personal Information (e.g.,) Account log-in credentials for our SwiftMR and SwiftSight web console (user ID and password, and the e-mail address used for two-factor authentication); a Social Security number or tax identification number where you are paid as an individual contractor or consultant; and information you volunteer for equal-opportunity reporting or to request an accommodation (such as race, ethnicity, gender, veteran status or a disability). In recruitment: your work authorization status, including whether you will require visa sponsorship (collected at application to determine eligibility for the role), and your Social Security number and government-issued identification, collected only after you accept a conditional offer for background checks and Form I-9 verificationDirectly from you
Our Service Provider
our background-check provider (after a conditional offer)
See above; for web-console credentials, only to authenticate users and secure the account; for contractor tax identification numbers, only for tax reporting; for information you volunteer, only for equal-opportunity reporting or the accommodation you request; in recruitment, only to determine eligibility, complete legally required verifications and conduct background checks; we use or disclose this sensitive personal information only for the purposes specified in 11 CCR §7027(m), as reasonably necessary and proportionate for those purposes, so the California right to limit does not applySee aboveNone
Commercial information (e.g.,) transaction information, purchase history and the payment details you provide for invoicingDirectly from you
Strategic Business Partner
To support your experience with our products and services and manage professional relationship with us, as outlined in our Privacy Policy
To improve our business operation
To process and respond to request, inquiries from you
To provide you with marketing materials or information
To provide customer support
To comply with applicable laws and regulations
To fulfill legal obligations
See aboveNone
Professional or employment-related information (e.g.,) Work history, job qualifications, resume/CV, cover letter, language skills, work authorization status, references, interview notes and assessment results, hiring decision, background-check results (only after a conditional offer)Directly from you; our recruitment platform provider (Workable); recruitment agencies and search firms; professional networking platforms (e.g., LinkedIn) and job boards (e.g., Indeed); your references; our background-check provider (Checkr), after a conditional offerTo evaluate your application and suitability for a role; to communicate with you and schedule interviews; to verify the information you provide; to make and record hiring decisions; to comply with employment and record-keeping laws and defend legal claims; with your agreement, to consider you for future roles; To manage your employment with AIRS Medical
To invite you to our events (symposia, lecture, etc)
AIRS Medical Affiliates in the Republic of Korea, Germany and Japan involved in recruiting; recruitment platform provider; recruitment agencies; background-check provider; professional advisors; governmental and law enforcement officialsNone
Internet or other similar network activity (e.g., browsing history, search history, clickstream data, interactions with our online channels)Cookies on the Channels
Our service providers
To operate online channels
To improve our business operation
To process and respond to request, inquiries from you
To provide you with marketing materials or information
To fulfill contractual obligations
To evaluate the effectiveness of our marketing campaign
To comply with applicable laws and regulations
To fulfill legal obligations
See aboveMarketing, Advertising, and Social Media Networks
Data analytics providers
Geolocation information (e.g., approximate location inferred from your IP address; we do not collect precise geolocation)Cookies on the Channels
Our service providers
To operate online channels
To maintain the security of online channels
To improve our business operation
To process and respond to request, inquiries from you
To provide you with marketing materials or information
To fulfill contractual obligations
To evaluate the effectiveness of our marketing campaign
To comply with applicable laws and regulations
To fulfill legal obligations
See aboveMarketing, Advertising, and Social Media Networks
Data analytics providers
Audio, electronic, or visual information (e.g., photographs and video recordings taken at our events and webinars, and recordings of support or sales calls where we tell you at the time)Directly from you
Our service providers
To operate online channels
To provide educational resources derived from our professional engagement
To improve our business operation
To process and respond to request, inquiries from you
To provide you with marketing materials or information
To fulfill contractual obligations
To evaluate the effectiveness of our marketing campaign
To comply with applicable laws and regulations
To fulfill legal obligations
See aboveNone
Inferences (e.g., preferences, characteristics, predispositions, behaviors, or attitudes derived from other personal information we collect)Cookies on the Channels
Our service providers
For recruitment inferences: application and assessment information described in the professional or employment-related information row
To improve our business operationSee aboveMarketing, Advertising, and Social Media Networks
Data analytics providers

The sale and sharing entries in this table do not apply to job applicant or candidate information described in Section B.4.

B.2. Retention and deletion

We retain each category of personal information collected through our online channels and business operations for as long as necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, or as required by applicable law. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, and whether we can achieve those purposes through other means. When personal information is no longer necessary for these purposes, we securely delete or anonymize it. Job applicant and candidate records are retained for four years from the date of application or the hiring decision, whichever is later, to meet federal and state record-keeping requirements, including California Government Code section 12946 (see "Notice to Job Applicants and Candidates").

Where a record is created or received later, or applicable law or a legal hold requires longer retention, we retain it for that longer period.

B.3. Your rights under state privacy laws

Subject to applicable state laws, you may exercise the following rights regarding your personal information. We will respond to such requests within 45 days (or unless a shorter timeframe is required by applicable law, such as opt-out requests), except where a justified extension is required. If additional time is needed, we may extend the response period by an additional 45 days, provided we notify you of the extension and the reason for it within the initial 45-day period. To exercise the rights that may be available to you as described below, please submit a privacy request through our online form or by email to privacy@airsmed.com. Job applicants and candidates may also submit requests to ghr@airsmed.com.

  • Right to Know: The right to request that we disclose what personal information we collect, use, disclose, and sell. This includes the categories and specific pieces of personal information we hold about you, the categories of sources, the purposes for collecting, selling or sharing it, and the categories of third parties to whom we disclose it.
  • Right to Deletion: The right to request that we delete Personal information we have collected about you.
  • Right to Data Portability: You can request a copy of your personal information from a business that can be transferred to another business in an readily usable format.
  • Right to Correction: You have the right to correct inaccuracies in your Personal information.
  • Right to Opt-Out: You have the right to opt-out of targeted advertising, the sale of your Personal information and profiling in furtherance of decisions that produce legal or similarly significant effects. You may request this right by contacting us through the methods stated above. Alternatively, you can opt out by using Global Privacy Control. We recognize and honor opt-out preference signals, such as the Global Privacy Control (GPC), as valid requests to opt out of the sale and sharing of your personal information and targeted advertising. When we detect a GPC signal from your browser, we will treat it as a valid opt-out request and apply it to the personal information associated with that browser. If we can identify you, we also apply the signal to associated personal information as required by law. You can enable GPC in a supporting browser or extension. For more information about GPC, visit globalprivacycontrol.org
  • Right to Non-discrimination: You have the right to be free from discrimination based on your exercise of your privacy rights. We do not discriminate or retaliate against you for exercising your privacy rights, including when you are a job applicant, employee or independent contractor.

For requests to know, delete or correct, we verify your identity by matching information you provide, such as your name and contact details, with our records. We may request additional information when reasonably necessary for verification. Requests to opt out of sale or sharing do not require identity verification.

B.3.1 Right to Limit Use of Sensitive Personal Information

Where required by applicable state laws, you have the right to request that we limit our use and disclosure of your Sensitive Personal Information to purposes that are necessary to provide the services you request. We will not collect or process your Sensitive Personal Information without first obtaining your explicit consent. To exercise this right, please contact us through the methods stated above. Please refer to our data category table above for specific examples of what constitutes sensitive information. This does not affect consent rights under other applicable state laws.

For California residents, the right to limit does not apply to the uses described in Section B.1.1, because we use and disclose sensitive personal information only as permitted by 11 CCR §7027(m).

B.3.2 Right to appeal

In case we are unable to fulfill your request, we will let you know why. To the extent available under applicable law, if you disagree with our decision, you can ask us to reconsider by filing an appeal within a reasonable period after receiving our response. You may file an appeal by contacting us via our online form or by emailing us at privacy@airsmed.com.

B.3.3 Shine the Light Law (CA only)

For residents of the state of California, you may ask us to stop sharing your information with third parties (including our affiliates) for their marketing by filling out our Privacy Contact Form.

B.3.4 Right to Explanation (MN only)

For residents of the state of Minnesota, you have the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions the consumer might have taken to secure a different decision and the actions that the consumer might take to secure a different decision in the future. You may also request to review the personal data used in the profiling and, if such data is inaccurate, to have it corrected and the profiling decision reevaluated.

B.3.5 Authorized Agents

As permitted by applicable state laws, you may designate an authorized agent to make a request on your behalf. To do so, you must provide the agent with written permission to submit the request. When an authorized agent submits a request on your behalf, we may require you to verify your own identity directly with us and explicitly confirm that you provided the authorized agent permission to submit the request. These verification requirements apply to requests to know, delete or correct, subject to applicable power-of-attorney exceptions; opt-out requests do not require identity verification.

B.4. Notice to Job Applicants and Candidates

If you apply for a role with AIRS Medical USA Inc., or we contact you about an opportunity, we collect the categories of personal information described in the table above — personal information (such as your name and contact details), professional or employment-related information (including your résumé, qualifications and work history), inferences we draw about your fit for the role and the sensitive personal information described above — in order to evaluate your application, communicate with you, verify the information you provide, make and record hiring decisions, comply with employment laws and, with your agreement, consider you for future roles. We retain application records for four years from the date of your application or the hiring decision, whichever is later. Your application is stored in a recruitment platform operated by our service provider and may be accessed by HR colleagues and hiring managers at our group companies in the Republic of Korea, Germany and Japan. We do not sell this information and do not share it for cross-context behavioral advertising. We do not use automated decision-making technology or AI-based screening tools to make or assist hiring decisions. Full details, including how to exercise your rights to know, delete and correct, are in the candidate privacy notice provided with the application form on our recruitment platform; you may also contact ghr@airsmed.com.

B.5. HIPAA Compliance

Our AI-powered image enhancement solutions and other offerings are designed for healthcare providers, who may share Protected Health Information (PHI) with us under the terms of our Business Associate Agreements (BAAs).

To ensure the highest level of data integrity and privacy, we maintain a comprehensive HIPAA Compliance Program. This program incorporates the administrative, physical, and technical safeguards required under HIPAA to protect Protected Health Information (PHI) throughout its lifecycle.

Our processing of PHI is strictly governed by Business Associate Agreements (BAAs) entered into with our customers, ensuring that data is used only for the specific purposes authorized by the healthcare provider.

AIRS Medical uses and discloses PHI only for the purposes identified in a signed Business Associate Agreement (BAA) with a Covered Entity or as otherwise required by law. We do not use or disclose PHI in any manner that is not permitted by the HIPAA Privacy Rule.

B.5.1 Your rights

In accordance with HIPAA and our Business Associate Agreements (BAAs) with healthcare providers, we support patients in exercising their privacy rights.

  • Right to Access and Amendment: You have the right to inspect, copy, and request amendments to your PHI maintained by your healthcare provider. As a Business Associate, AIRS Medical will cooperate fully with your healthcare provider to facilitate these requests as prescribed under our BAA.
  • Right to an Accounting of Disclosures: You may request a list of certain disclosures we have made of your PHI for purposes other than treatment, payment, or healthcare operations.

Since your healthcare provider (the "Covered Entity") is primarily responsible for managing your medical records, we recommend submitting these requests directly to them. AIRS Medical’s Compliance Officer will work closely with your provider to process and fulfill such requests in a timely manner.

B.5.2 Breach Notification and Incident Response

AIRS Medical maintains a proactive incident response framework to identify, investigate, and mitigate any potential security incidents. In the event of a breach of unsecured Protected Health Information (PHI), we fulfill our reporting obligations with the utmost transparency and urgency.

  • Timely Notification: We notify the affected Covered Entity of any breach of unsecured PHI without unreasonable delay, and in no case later than sixty (60) calendar days after the discovery of the incident in accordance with HIPAA. Discovery includes when we knew, or through reasonable diligence would have known, of the breach.
  • Comprehensive Investigation: Upon detecting a potential incident, AIRS Medical conducts a thorough risk assessment to evaluate the nature of the data and the extent of the risk involved. We specifically determine whether the incident involves 'unsecured PHI' as defined under HIPAA; however, by maintaining NIST-standard destruction and robust encryption, we ensure that your PHI remains indecipherable to unauthorized parties. These rigorous safeguards are designed to prevent your data from being classified as 'unsecured,' thereby providing an additional layer of legal and technical protection. We assess any encryption or destruction safe harbor for the data involved in each incident.
  • Collaborative Support: Our notification to the Covered Entity includes all essential information, such as the identity of affected individuals and the circumstances of the breach, to support the Covered Entity in their obligation to notify the affected parties.

B.5.3 Retention

AIRS Medical retains personal information only as long as necessary to fulfill the purposes outlined in our services or to comply with applicable laws, including HIPAA’s record retention requirements. When a business or legal necessity no longer exists, we ensure the secure deletion or permanent destruction of data.

  • For certain products and service offerings, we may store patient information (PHI and DICOM images) in a cloud database for a limited period to provide product functionality and ensure proper use of the products. Such data stored temporarily in the cloud is retained only for the duration specified by the customer and is permanently deleted after that period.

B.5.4 Additional Notice for California Residents

In addition to federal HIPAA standards, AIRS Medical strictly adheres to the California Confidentiality of Medical Information Act (“CMIA”) for residents of California.

  • Restricted Use and Non-Monetization: We do not sell, rent, or otherwise monetize any medical information or Protected Health Information (PHI) processed under our Business Associate Agreements (BAAs).
  • Authorized Disclosures: Consistent with California Civil Code § 56.10, all disclosures of medical information are strictly limited to essential operations such as treatment and payment or instances of valid legal mandates (e.g., court orders, warrants, or subpoenas).
  • Contractual Integrity: Acting in our capacity as a Business Associate under HIPAA (Contractor under CMIA), we fulfill our duty to preserve data confidentiality as required under California Civil Code § 56.101(a). We do not disclose information without explicit contractual authorization from the relevant healthcare provider. While certain disclosures compelled by law may proceed without an individual’s signed authorization, such actions are taken only when legally mandated and within the scope of our agreement with the Covered Entity.
  • Extended obligations: We extend these confidentiality obligations to all subcontractors and service providers through formal written agreements, ensuring end-to-end protection of your data.