Privacy Policy

At myMed (“we,” “us,” or “our”), we are committed to protecting your privacy and handling your health information responsibly. This Privacy Policy explains what data we collect, how we use and share it, how we protect it, and the rights you have over it when you use the myMed digital health wallet application (the “App”). This Policy should be read together with our Terms and Conditions.

1. Who we are

myMed is operated by Motive Labs Inc., a company incorporated under the laws of Barbados, registration number 54452, registered office at 14 Philip Drive, Pine Gardens, St. Michael, Barbados. For privacy questions or to exercise your rights, contact: contact@motivelabs.net

2. Data We Collect

  • Identity and Authentication Data. Your name, email address, and mobile phone number, used to create your account and to send one-time verification codes by SMS and email for secure sign-in.
  • Patient Health Data. Medical records, lab results, clinical summaries, and provider communications that you upload or that are imported through a connected integration. This data is structured using internationally recognized healthcare data-interoperability standards, so it can be organized consistently and shared securely with your chosen physician.
  • Connected Device and Ecosystem Metrics. Health and wellness data from third-party ecosystems, including Apple Health, Google Health Connect, wearable devices, and smartphones (e.g., heart rate, sleep, steps, and activity). When you connect one of these integrations, we import the complete set of data categories you have authorized through that platform’s own permission screen; we do not offer separate in-app controls to import only some of that authorized data. You manage what is shared at the platform level, through your Apple Health or Google Health Connect settings.
  • Technical and Usage Data. Limited technical information (such as device type, app version, and crash logs) used to keep the App secure and functioning correctly.

3. Legal Basis for Processing

Because your health information is sensitive personal data under the Barbados Data Protection Act, 2019-29, we only process it where we have a valid legal basis, which will typically be one or more of the following:

  • Your explicit consent — required before we import, store, or use your health data, and separate from your general acceptance of the Terms and Conditions (see Section 4 for the public-health research use specifically);
  • Performance of a contract — to provide the wallet features you sign up for;
  • Legal obligation — where we must retain or disclose data to comply with the law; and
  • Legitimate interests — for example, keeping the App secure, which we balance against your privacy rights.

4. How We Use Your Data

  • Identity Verification. Sending SMS and email verification codes to prevent unauthorized account access.
  • Data Aggregation. Consolidating your historical medical results and wearable metrics into a single dashboard for your own use.
  • User-Directed Sharing. Facilitating secure, encrypted transmission of medical reports you choose to share with your physician, strictly at your direction.
  • Service Operation and Security. Maintaining the technical performance, reliability, and security of the App.

4.1 Disaggregated and De-Identified Data: Research, Public Health, AI Development, and Analyticsites

We may aggregate and de-identify data by removing direct identifiers such as your name, email, phone number, and exact date of birth.  We may use and share this information only where it has been de-identified for the following purposes:

  • Public Health and Research. Informing national health policy, tracking wellness trends, and supporting clinical guideline development, including sharing with public health authorities, research institutions, or government agencies.
  • AI and Model Development. Training, testing, and improving artificial intelligence and machine learning models, including models used to power features within myMed and, where disclosed to you at the time, models developed for use beyond myMed.
  • Commercial Analytics. Generating aggregate insights, trend reporting, and analytics that may be used internally or provided to commercial partners, for example to support product development, market research, or business planning.

We obtain your separate, opt-in consent before using your data for these purposes, presented apart from your acceptance of this Policy and our Terms and Conditions. We ask for this consent in two parts, since they are meaningfully different uses: (a) public health and research, and (b) AI development and commercial analytics. You may consent to one without the other, and you may withdraw either consent at any time through the App’s privacy settings, without affecting your ability to use the rest of the App.

  • Your Control. Participation in these uses is separate from your use of the core wallet features. You may decline or withdraw consent at any time through the App’s privacy settings without affecting your ability to use the rest of the App.

5. Data Storage, Architecture, and Security

  • Cloud Infrastructure. Your data is hosted on reputable, enterprise-grade cloud infrastructure that maintains healthcare-relevant security certifications, including network isolation, firewalls, and continuous monitoring. We select and regularly review our infrastructure providers for their security and compliance posture.
  • Encryption. Your data is encrypted both in transit (moving between your device and our servers) and at rest (while stored).
  • Interoperability and Access Controls. Health data is organized using internationally recognized healthcare interoperability standards and is accessed only through access-controlled, audited interfaces restricted to authorized systems and personnel.
  • Development and Operations. Our platform is built and maintained with the support of specialist technology partners who are contractually bound by data processing agreements and confidentiality obligations at least as protective as those described in this Policy.

6. How Your Data Is Shared

  • With Your Explicit Consent. We share your health data with your designated physician or clinical team only when you use the in-app “Share” feature. Sharing with a given physician covers the full contents of your wallet, rather than selected categories; we do not currently offer a way to share only part of your wallet with an individual physician. You control who sees your data and can revoke access at any time; we do not notify the physician when you revoke their access.
  • With Verified Emergency Clinics. We also offer an option to share the full contents of your wallet with emergency clinics that have gone through our verification process, so that emergency responders may access your health information in an emergency. This feature is off by default and is only activated if you choose to turn it on through an affirmative, specific action in the App’s privacy settings. You may turn it off again at any time.
  • With Service Providers. We share data with vetted service providers who help us run the App — for example, cloud hosting and SMS/email delivery for verification codes. These providers act only on our instructions and are bound by written data processing agreements requiring them to protect your data and use it solely to provide their service to us.
  • Disaggregated and De-Identified Data Sharing. As described in Section 4.1, de-identified and aggregated data may be shared with public health policymakers, researchers, AI development partners, or commercial partners for analytics purposes, subject to your participation choice.
  • Legal Requirements. We may disclose your information where required by a binding legal order, subpoena, or applicable regulatory authority.
  • Business Transfers. If myMed is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction, subject to equivalent privacy protections.

7. Cross-Border Data Transfers

  • Where Data May Be Processed. Our service providers may process and store data outside Barbados.
  •  Where this occurs, we will only transfer your data where the receiving country provides an adequate level of protection, and appropriate safeguards are in place to protect your data, your rights, and your ability to seek effective legal remedies. These safeguards may include contractual safeguards, or other legally recognized measures designed to protect your data.
  • In limited circumstances where an adequate level of protection or appropriate safeguards are not available, we will only transfer your personal data where permitted under the Data Protection Act, 2019-29, including where you have explicitly consented to the transfer, where the transfer is necessary to perform a contract with you, where it is required for an important public interest reasons to establish or defend legal claims, to protect vital interests, or where the transfer is made from a public register in accordance with the Act.
  • We will continue to take reasonable steps to ensure that any person or organisation processing your data on our behalf protects it in accordance with applicable data protection laws, including through contracts with our providers and, where available, hosting choices in jurisdictions recognized for strong data protection standards.
  • Details on Request. You may contact us for further information about the categories of recipients and general locations involved in processing your data and the specific safeguard or derogation relied upon for a given transfer.

8. Data Retention

  • How Long We Keep Data. We retain your health data for as long as necessary to fulfil the purposes for which it was collected, including providing our Services, maintaining your account, complying with legal and regulatory obligations, resolving disputes, and enforcing our agreements. We do not retain your data for longer than is necessary for these purposes.
  • Deletion of Your Data. When you request deletion of your account, we will delete or irreversibly de-identify your personal data so that it will no longer be linked to you, where reasonably possible. We may retain certain information where required by law or where necessary for legitimate record-keeping purposes, such as financial, legal, or regulatory obligations.
  • Where we have shared your personal data with third parties who are required to delete it, we will take reasonable steps to notify them of your request, unless doing so is impossible or would require disproportionate effort.

9. Your Rights and Controls

  • Access and Portability. You may request confirmation as to whether we process personal data concerning you and, where we do, to request a copy of that personal data, together with a description of the purpose of processing, the categories of the data concerned, the recipients to whom the data has been or will be disclosed, the anticipated retention period and the existence of your other rights under the Data Protection Act 2019-29.
  • Where our processing of your personal data is based on your consent or is necessary for the performance of a contract with you and such processing is carried out by automated means you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit the data to another controller.
  • Exporting your Health Records. In addition to your statutory rights, the App allows you to request a copy of the personal data we hold about you and export your health records from the App at any time.
  • Correction. You can, request correction of inaccurate or incomplete data.
  • Erasure. You mayrequest deletion of your account and associated health data. We will action valid erasure request without undue delay subject to legal or clinical retention requirements that override the request.
  • Withdraw Consent. Withdrawing consent to any processing based on consent is possible — including via wearable integrations and participation in research, AI development, or commercial analytics. You can do so at any time via the App’s privacy settings, without affecting processing already carried out. Withdrawing consent may limit or disable the features that rely on it.
  • Revoke Integrations. Apple Health, Google Health Connect, or other integrations can be disconnected by you at any time, through your device settings. Because we import the full authorised dataset (see Section 2), disconnecting stops the entire integration rather than individual data categories.
  • Restriction of processing. You may request that we restrict the processing of personal data concerning you, including where you dispute the accuracy of your personal data, object to our processing, require the data to establish, exercise, or defend legal claims, or where the processing is unlawful but you prefer restriction rather than erasure. 
  • Object to processing likely to cause damage of distress. You may request that we stop or not begin a specific kind of processing if it is likely to cause substantial or unwarranted damage or distress.
  • Object to direct marketing. You may request that we stop using personal data concerning you for the purpose of direct marketing
  • Not subject to solely automated decision-making. You may request not to have decisions about you made solely by automated processing where those decisions have legal or similarly significant effects on you.
  • Complaint. If you believe your data has been mishandled you may lodge a complaint with the Barbados Data Protection Commissioner, or another applicable supervisory authority,

To exercise any of these rights, contact us using the details in Section 1. We will respond within the timeframe required by applicable law.

10. Data Breach Notification

If we become aware of a security incident affecting your personal data, we will assess the risk and, where required by the Barbados Data Protection Act, notify the Data Protection Commissioner in the statutory timeframe if the incident is likely to result in a high risk to your rights and freedoms.

If we become aware of a personal data breach that affects you, we explain the nature of the breach, outline the steps we have taken or propose to take to address it, and, where appropriate, any steps we recommend you  take to reduce any potential harm.

11. Children’s Privacy

The App is intended for users who are at least 18 years of age, or the age of majority in their jurisdiction. A minor for the purposes of this Policy means a person under the age of 18 years.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our features or in applicable law. We will notify you of material changes by displaying a prominent in-app alert or sending an email at least [30] days before the change takes effect, and where the change relates to processing based on your consent, we will seek your renewed consent before that processing begins.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your data, contact us at contact@motivelabs.net.