Last updated: December 26, 2023

Introduction

Kahun Medical Ltd. (“Kahun”, “we”, “us” or “our”) respects the privacy of its users (“User(s)”, “your” or “you”), and is committed to protecting your privacy and the personal information that you share with us in connection with the use of the Kahun Medical web and mobile applications (the “App”), the main website, available at www.kahun.com or any other related service that links to this privacy policy (the “Website” or “Site”, and together with the App, the “Services”). 


To ease your navigation in this privacy policy (“Privacy Policy”), you may use the following headlines:

1. Scope

2. Preliminary Notes

3. Your consent

4. Information we collect

5. Using cookies and similar web technologies

6. Our legal basis for use of your information

7. The purpose for processing your information

8. Sharing information with third parties

9. Where do we store your personal information

10. Data retention and security

11. Your privacy rights

12. Minors and third-party information provided by you

13. Changes to the Privacy Policy

14. General

15. Have any questions?

1. Scope 

  1. This Privacy Policy is designed to describe the processing activities taken by Kahun (or by third parties on Kahun’s behalf) of Personal Data of Users. “Personal Data” or “Personal Information” means any information that can be used by us or others, either alone or together with other data, to uniquely identify an individual or be associated with an individual, whether a User (as the term defined in our Terms of Service), or a third party.
  2. A data subject may be one or more of the following: (i) a healthcare professional user (HCP) seeking to support a medical decision or diagnosis with medical research (“HCP”), (ii) a patient of an HCP user, whether submitting Personal Data directly or that such data is submitted about them (“Patient”); (iv) A visitor of the web App or Site (“Visitor”).
  3. This Privacy Policy does not apply to (i) Personal Data processed by us as a data processor, as the term processor is defined by applicable regulation; Except when the Services carry a user interface and Personal Data is submitted directly by the User; or, (ii) Personal Data related to business partners or any person or entity with which we collaborate on a business-to-business basis, or (iii) information that was anonymized, aggregated in a form that made it non-personal, or statistical data.

2. Preliminary Notes 

  1. Not for minors. If you are under the age of 16, do not use the Services, unless your parent or legal guardian is doing so on your behalf.
  2. Binding Agreement. This Privacy Policy constitutes an integral part of our Terms of Service (“TOS”), and unless explicitly mentioned otherwise in another agreement with you, is a legally binding agreement. 
  3. Special jurisdictions and regulations. This Privacy Policy was designed with the European data protection regulations in mind (“GDPR”), however, given the country of your residency, different rules may apply to your Personal Data. If you are a resident of California, we advise you to additionally refer to our CCPA and CPRA Privacy Statement.
  4. Data Controller. With respect to Visitors Users, Kahun acts as a Data Controller. Otherwise, Kahun acts as a data processor and follows the instructions for data processors, as the case may be.
  5. Data Protection Officer (DPO). If you have any questions or requests regarding the data collected or otherwise processed under this Privacy Policy, including requests regarding your privacy rights or the transfers of Personal Data, please contact our Data Protection Officer (DPO) at: privacy@kahun.com. Please include sufficient details about your inquiry or request, to allow us to verify your request and address it in a timely manner.
  6. Changes and updates to this Privacy Policy. We may modify or update this Privacy Policy at any time, to reflect changes in our Services, data processing practices or to conform to a regulatory requirement. Such changes will be effective immediately upon the display of the revised Privacy Policy. The last revision date will be reflected in the "Last Updated" heading. If we make material changes to this Privacy Policy, we will make our best efforts to notify you, by email if possible, or by means of a notice on our Website.
  7. Your Personal Data. You are not required by law to provide us with Personal Data and you do so voluntarily at your free will. You can always avoid providing us with certain Personal Information, however, you acknowledge that it may prevent us from providing you with certain Services, or, may result in ineffective usage of Services. We sometimes process Personal Data about data subjects that were not provided to us by them, for example, when an HCP User, submits Personal Data about their patients or a case study; in such cases, we require the HCP to hold a legal basis for the processing of such Personal Data. 
  8. Beta Versions. Some portions of functions of the Services may be provided as a Beta, which means it is a pre-release version intended for testing purposes. When a Service or any part thereof is marked as “Beta”, you may encounter bugs, errors, or other issues that could affect functionality. We do not guarantee the accuracy, completeness, or reliability of the information or features within beta versions. Changes and updates may occur frequently, impacting your experience. While we take precautions to safeguard your data, as with any beta version, there may be potential security risks. Avoid using sensitive or confidential information during this testing phase.

3. Your Consent 

  1. Please read this Privacy Policy before accessing and using the Services. By entering, connecting to, accessing, and/or using our Services, you agree to be bound by the terms and conditions set in this Privacy Policy, including the collection and processing of your Personal Information. In certain cases, you will have to provide more prominent consent, for example, by checking a box and acknowledging your informed consent, prior to using a specific function of Services.
  2. Certain information we may collect, such as general usage information, device information, analytics, statistics, or any other data that enables us to provide the Services and monitor against fraud, is collected as part of our legitimate interest. You can find a further explanation below, under the “Legal Basis” section.
  3. Personal information about third parties and respective consent:

a. When you use certain functionalities of the Services, you may end up submitting the Personal Information of others. When doing so, you acknowledge and agree that such third-party information is submitted based on their lawful consent, contract or any other lawful basis applicable to your jurisdiction and/or profession, as the context may be. 

b. You hereby undertake to not submit or otherwise transmit to us any Personal Information, including Personal Health Information (PHI), unless you have a documented lawful basis to do so. We reserved the right (however not obliged), to request that you demonstrate to us any such consent.

4. Information we collect 

  1. The Personal Information we may process originates from one or more of the following sources: (i) Information you actively provide to us, including by way of contacting us or interacting with our Services; (ii) Information automatically accessed or collected while you use our Services or while you browse the Website, such as cookies and tags that are required for their functionality; (iii) Information submitted about your conditions by a User of the Services, based on your consent to them.

  • When you use the Website (Visitors)
Type of Information
How do we use it and for how long?
Online Identifiers: We process certain online identifiers such as IP addresses, cookies, user agent (namely, in addition to your IP address, your browser’s type, version, language and country from which you access the Website or Services).
We may either directly or indirectly collect our Visitors’ Online Identifiers, for one or more of the following purposes:

a. Extracting analytics and statistical information about the visits to our Website.
b. Preventing and protecting against spam or fraud, including attempts to overload or attack our Services, as part of our legitimate interest.
c. Necessary cookies are used as part of our legitimate interest and for purposes of the Website’s functionality.
d. In certain cases, and upon your explicit consent (if you are an EU/EEA or UK resident), third-party cookies and tags will be used for purposes of marketing our Services.

We retain online identifiers for as long as required to achieve each of these purposes or until deleted by you via your browser’s settings. Cookies’ expiry dates are varied as a dependency of the type and purpose and can be found in our cookies policy.
Device Information: We may automatically collect certain information about the device from which you access the Website or Services, such as device type (mobile/desktop), type, version and language of your operating system.
Based on your consent, or in certain cases, our legitimate interest, we may process device information for compatibility purposes and learning of the best way to access our Services.
Analytics and Activity (online): We also process certain information related to your use of the Website or App such as your queries, clicks, selection of answers suggested to you, and other actions related to your use of the Services and our ability to provide you with as accurate and relevant Services as possible.
We use this data to operate and manage our Services and make them accessible to you in the most accurate manner. In certain cases, we may use functional cookies to help you retain previous queries (also, “Cases”) you submitted, for the purpose of easing your use of the Services and making them effective to your needs.

We also retain this information for purposes of quality validation and assurance, for example, when we seek to validate the credibility or consistency of output over time.
Contact Details: In the event you contact us for support, feedback, or other inquiries or requests, either through an online form available on the Website, by sending us an email, or by other means of communication we make available (such as submitting a bug report or filling in a survey), you will be requested to provide us with your full name, email address, your phone number, occupation (optional), and the subject matter of your inquiry.
We will use this information for our legitimate interest and solely to respond to your inquiries and provide for the purpose of responding to your inquiries and providing you with the support or information you have requested. We retain such information for as long as needed to provide you with the inquiry requested or as required under applicable law.
Subscription: If you voluntarily subscribe to our email communications, you will be asked to provide us with your email address. You can unsubscribe at any time using the unsubscribe option within the body of the email sent to you or rather by contacting our Data Protection Officer at privacy@kahun.com.
We will use your email address to send you information related to our Services and to keep you up to date regarding new Services, as well as provide you with tips related to our Services, and promotional and marketing emails, all subject to your consent. We retain this information so long as you didn’t instruct us otherwise.
  • When you sign-up and/or use the Services as an HCP User: in addition to the Personal Information processed about Visitors, the following will be further processed about the usage of HCP.
Type of Information
How Do We Use It?
Account Information: if you choose to sign-up we will process your email address (also your user name) and your selection of specialty.
We use this data to allocate an account for you, maintain it and secure access to it. Additionally, when you log in to the Services, additional functionalities and services may be available to you, such as a record of your previous Cases. We retain Account Information for as long as you maintain your account with us. In certain cases, where required by applicable regulation we may retain for a longer period of time.
Online Identifiers: When you use the App as an HCP our system will generate a random identifier that will allow us to attribute your Cases to your account. Additionally, the following Online Identifiers may be processed to operate your use: IP address, functional cookies, and user agent.
Online identifiers are used for attribution and protection of your use and your Cases, and for your management of Cases and Accounts. Functional cookies are used upon your consent (if you are based in the UK or EU), to help you “remember” previous Cases you submitted.
Input, free text and Cases
When you use the App to support a diagnosis or other medical decision you make, you may submit Personal Data about third-party patients (actual, prospective or hypothetical). In this case, the information will be similar in nature and type to what is detailed under “Patient Information” below and shall be reflected by you to such third-party data subjects.
This information is used to provide the core Services of the App, and retained for as long as necessary to process the Services, and as long as you choose to retain Cases history. We also retain this information for purposes of quality validation and assurance, for example, when we seek to validate the credibility or consistency of output over time.

We explicitly ask you to not submit to the Services any Personally Identifiable Information. If you submit a free text and include information of such a nature, you are doing so at your sole risk and responsibility.
Such information will be processed as a general text input.
  • Patient and/or Third Parties

in addition to the Personal Information processed about Visitors, the following may be processed about third parties whose Personal Data may be submitted by Users:

Type of Information
How Do We Use It?
Data concerning health condition. Such as symptoms and medical conditions, submitted by you in an anonymous form.
The data is used to provide the Services and provide you with further suggestions that may help you or your HCP to better understand a medical condition and/or diagnosis.
Demographic Information. Due to the relevance of age and gender to an analysis of a Case, we may ask you to submit this information when you use the Services.
To provide the Services.
Identifiers. Unless provided voluntarily by you, and unless directly necessary for the Services, no identifiers other than online identifiers will be processed.

5. Using cookies and similar web technologies

  1. We may use cookies and similar web technologies to help us with a better understanding of how you use our Services, including those offered by Third Party Service Providers (as defined below). These technologies are used to maintain, provide and improve our Services on an ongoing basis, and in order to provide a better experience to our Users. For example, these technologies enable us to: (i) keep track of and “remember” our Users’ preferences in authenticated sessions, (ii) secure our Services by detecting abnormal behaviors, (iii) identify technical issues and improve the overall performance of our Services, (iv) and create and monitor analytics and usability of the Services.

6. Our legal basis for processing Personal Information

We collect, process and use your information for the purposes described in this Privacy Policy, based at least on one of the following legal grounds:

  1. With your consent upon accessing and/or registering to the Services. Such consent is made by an affirmative action you are required to take, that acknowledges your consent to this Privacy Policy and processing Personal Data. You have the right to withdraw your consent at any time.
  2. Legitimate Interest:
  • For our legitimate interest when processing is required to provide our Services, to make the functional and compatible with your device, to maintain and improve our Services, for quality assurance of the Services, including to maintain our technology’s longevity, accuracy and validity, to learn about usages, to develop new services and features and to customize the Services overtime as per the categories and types of Users.
  • For our legitimate interest to protect our Services and to safeguard any access to or use of the Services. This means that we process your information for purposes of detecting, preventing, or otherwise addressing fraud, abuse, security, safety, usability, functionality or technical issues with our Services, protecting against harm to the rights, property or safety of our online properties, our Users, or the public as required or permitted by law.
  • For our learning purposes of how Users prefer to use the Services and what are the features that better serve them, to test system output and compare them for quality purposes.
  • We process certain information such as cookies and other online technologies for our legitimate interests while applying appropriate safeguards that protect your privacy.

3. If required, to enforce legal claims, including investigation of potential violations of this Privacy Policy; and in order to comply and/or fulfill our obligations under applicable laws, regulations, guidelines, industry standards, contractual requirements, legal process, subpoena or governmental request, as well as our Terms of Use.

  1. Contract: if you partner with us on a business-to-business level, or otherwise engage in a contract with us, we will process Personal Information to prepare for a contract, propose a business offering, or fulfilling a contractual obligation with the organization you represent.

7. Purpose for processing Personal Information

In addition to the purposes described next to each data category, we may use information that we collect about you for the following purposes:

  1. To provide, operate and improve our Services and manage our operation;
  2. To generate analysis and insights for our Users and to better understand how they use our Services; 
  3. To send you updates, notices, notifications, announcements, and additional information related to the Services;
  4. To be able to manage your account and provide you with customer support;
  5. To create cumulative statistical data and other cumulative information that is non-personal, which we and/or our business partners might make use of in order to operate and improve our Services;
  6. To perform functions or services as otherwise described to you at the time of collection;
  7. To prevent, detect, mitigate, and investigate fraud, security breaches or other potentially prohibited or illegal activities;
  8. To comply with any applicable rule or regulation and/or respond to or defend against legal proceedings brought against us or our affiliates.


Any information you submit to us via the Services is used respectively for the purposes indicated in the relevant form or webpage.

8. Sharing information with third parties

We keep the information processed by us in strict confidence and only share your information with third parties in very limited circumstances and for very specific purposes, as described below:

  1. We are partnering with a number of selected service providers, whose services and solutions complement, facilitate and enhance our own. These include hosting, database and server co-location services (e.g., Amazon (AWS)), AI-Language Models (AILM) or Large Language Models (LLM), such as OpenAI (which Privacy Commitments are available at https://openai.com/enterprise-privacy#our-commitments), data analytics services (e.g. Google Analytics) and session replay records for analytic purposes such as crashes, functionality and usability (e.g. MixPanel) and our business, legal and financial advisors (collectively, “Third Party Service Providers”). 

    Such Third Party Service Providers may receive or otherwise have access to certain Personal Information, depending on each of their particular roles and purposes in facilitating and enhancing the Services, and may only use your Personal Information for such purposes. Disclosures of Personal Information are subject to the respective third party’s undertaking of confidentiality obligations, and the prevention of any independent right to use this data except as required to help us provide you with the Services. 
  1. Our auditors, consultants, investors, and contractors with whom we may share samples of Personal Data on a need-to-know basis only and under strict confidentiality obligations.
  2. Law enforcement, legal proceedings, and as authorized by law: We may disclose or otherwise allow access to Personal Information pursuant to a legal requirement or request, such as a subpoena, search warrant or court order, or in compliance with applicable laws and regulations. Such disclosure or access may occur with or without notice to you if we have a good faith belief that we are legally required to do so, or that disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing.
  3. Protecting Rights and Safety: We may share your Personal Information with others, with or without notice to you, in cases of emergency or if we believe in good faith that this will help protect the rights, property or personal safety of our company, any of our Users, or any members of the general public.
  4. Our Staff: We may share Personal Information internally with our staff at Kahun, for the purposes described in this Privacy Policy. Should we undergo any change in control, including by means of merger, acquisition, or purchase of substantially all of its assets, your Personal Information may be shared with the parties involved in such an event. If we believe that such change in control might materially affect your Personal Information then stored with us, we will notify you of this event and the choices you may have via e-mail and/or prominent notice on our Website, App or Services.
  5. Change of control: In the event that Kahun is acquired by or merged with a third-party entity, we reserve the right to transfer or assign the information we collected as part of such merger, acquisition, sale, or other change of control.
  6. In the unlikely event of a bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors’ rights generally, we may not be able to control how your information is treated, transferred, or used.
  7. Tests, research and validation partners. From time to time we may collaborate with selected third-party partners for purposes of (i) research, testing and/or validation of our Services, or, the output they provide, or, (ii) for purposes of helping other products improve by using our technology and Services. An example may be using LLM (Large Language Modeling) technologies, which may process Personal Information on our behalf for the purpose of generating responses that are tested and validated by our Services. Such technologies do not store or retain any personal information provided during the conversation, and may only retain Personal Information for 30 days for fraud monitoring purposes.

For the avoidance of doubt, we may share your Personal Information in additional manners, pursuant to your consent, or if we are legally obligated to do so. Additionally, we may transfer, share or otherwise use Non-Personal (including anonymized, statistical or aggregated) Information at our sole discretion and without the need for further approval.

9. Where we store your Personal Information

  1. Your information will be maintained, processed and stored by us and our authorized affiliates (if applicable) in secure cloud storage, provided by our Third Party Service Providers based in the United States.
  2. While the data protection laws in jurisdictions where the information is physically stored may be different than the laws of your residence or location, please know that we, our affiliates and our service providers that store or process your Personal Information on our behalf, are each committed to keeping it protected and secured, pursuant to this Privacy Policy, applicable legislation and best industry standards, regardless of any lesser legal requirements that may apply in a particular jurisdiction. You hereby accept the place of storage and the transfer of information as described in this Privacy Policy.

10. Data retention and security

  1. As a matter of principle, we retain Personal Data for no longer than necessary to achieve the purpose for which it was collected. Further, when feasible, we process Personal Data on a temporary basis. The Personal Data we process to provide, maintain, and develop the Services, is not attributed, connected or associated with any identified individual, to ensure their privacy protection.
  2. We retain the Personal Information we collect or receive from you only for as long as your registered account exists in our system and as needed to provide you with the Services and as otherwise necessary to comply with applicable laws and regulations.  If you withdraw your consent to us processing your Personal Information, including by deleting your account, we will delete your Personal Information from our systems, except to the extent such data in whole or in part is required to comply with any applicable rule or regulation and/or to respond to or defend against legal proceeding brought against us or our affiliates.
  3. We take great care in implementing and maintaining the security of the Services and of your Personal Information. We employ industry standard procedures and policies to ensure the safety of your information, reduce the risks stemming from loss of information and prevent unauthorized use of any such information. However, we do not and cannot guarantee that unauthorized access will never occur and reiterate that no measure can provide absolute information security.

11. Your privacy rights

  1. The following rights apply to certain individuals, depending on their country of residence:
  • Right to know: You have a right to know (also called, right to access) Personal Data held about you. Your right of access may normally be exercised free of charge; however, we reserve the right to charge an appropriate administrative fee where permitted by applicable law.
  • Right to rectify: You have the right to request that we rectify any Personal Data we hold that is inaccurate or misleading.
  • Right to be forgotten: You have the right to request the erasure/deletion of your Personal Data (e.g. from our records). Please note that there may be circumstances in which we are required to retain your Personal Data, for example for the establishment, exercise, or defense of legal claims.
  • Right to object: You have the right to object, to or to request restriction, of the processing. Please note, given the nature of the Services and structure of the technology, the capability to exercise this right may be inherently limited. In which case your only remedy will be be to cease your usage of the Services. 
  • Right to data portability: You have the right to data portability in certain contexts. This means, that in case we indeed retain Personal Data about you, you may have the right to receive your Personal Data in a structured, commonly used and machine-readable format, and that you have the right to transmit that data to another controller.
  • Right to withdraw consent: You have the right to withdraw your consent at any time, in circumstances where such consent was given by you. Please note that there may be circumstances in which we are entitled to continue processing your data, in particular, if the processing is required to meet our legal and regulatory obligations. Also, please note that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
  • You have a right to lodge a complaint with your local data protection supervisory authority (i.e., your place of habitual residence, place of work or place of alleged infringement) at any time or before the relevant institutions in your place of residence. We ask that you please attempt to resolve any issues with us before you contact your local supervisory authority and/or relevant institution.
  1. You can exercise your rights by contacting us at privacy@kahun.com. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly according to applicable law or inform you if we require further information to fulfill your request.

    Verification
    : When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance, if your request is manifestly unfounded or excessive. If your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initially requested, we will address your request to the maximum extent possible, all according to applicable law.

12. Minors and third-party information provided by you

  1. To access or use the Services, you must be over the age of sixteen (16), and in any case, not underage according to the legislation in your country of residence. Kahun does not knowingly process Personal Information from children under the age of sixteen (16) and does not wish to do so. We reserve the right to request proof of age at any stage so that we can verify that minors under the age of sixteen (16) are not using the Services. 
  2. If it comes to our attention that a person under the age of sixteen (16) is using the Services, we may prohibit and block such User from using the Services and will make all efforts to promptly delete any Personal Information with respect to such User.
  3. If you are submitting to the Services any Personal Information relating to any minor child, you hereby represent and warrant that you have received all the necessary legal consents or approvals or that you are the parent or legal guardian and have the actual authority and legal right to upload, submit, disclose or otherwise share the Non-personal Information and/or Personal Information and/or any other form of sensitive information, on the minor’s behalf.

13. Changes to the Privacy Policy

The terms of this Privacy Policy will govern the use of the Services and any information collected therein. Kahun reserves the right to change this Privacy Policy at any time, so please revisit this page frequently. We will provide notice of substantial changes to this Privacy Policy on the homepage of the Website and/or we will send you an e-mail regarding such changes to the e-mail address that you may have provided to us. Such substantial changes will take effect seven (7) days after such notice was provided on our Website or sent by email. Otherwise, all other changes to this Privacy Policy are effective as of the stated “Last Updated” date and your continued use of the Website after the Last Revised date will constitute acceptance of, and agreement to be bound by, those changes.

14. General

This Privacy Policy, its interpretation, and any claims and disputes related hereto, shall be governed by the laws of the State of Israel, without respect to its criminal law principles. Any and all such claims and disputes shall be brought in, and you hereby consent to them being litigated in and decided exclusively by a court of competent jurisdiction located in Tel Aviv, Israel.

This Privacy Policy was written in English and may be translated into other languages for your convenience. If a translated (non-English) version of this Privacy Policy conflicts in any way with the English version, the provisions of the English version shall prevail.

15. Have any questions?

If you have any questions (or comments) concerning this Privacy Policy, you are welcome to send us an email at: privacy@kahun.com and we will make an effort to reply within a reasonable timeframe.

Mapped medical knowledge at your fingertips
© 2024 Kahun Ltd. All rights reserved.