Privacy policy for use of the application
Incubeats Privacy Policy
Effective date: 22/11/2025
Incubeats Tech Ltd (“Incubeats”, “we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you use the Incubeats App (“App”), whether for hospital programs or private use.
By using the App, you agree to this Privacy Policy. Please read it carefully.
1. Roles and Responsibilities
Hospital-Based Use
When using the App in connection with a hospital program (e.g., neonatal care), the hospital you select in the App is the Data Controller under UK GDPR / EU GDPR.
Incubeats acts as a Data Processor on the Hospital’s documented instructions, collecting, storing, and transmitting your Personal Data for the hospital’s care programs.
Private Use
When using the App independently of any hospital program, Incubeats acts as the Data Controller for the Personal Data you provide.
Hospitals will not access your data unless you explicitly share it.
2. Information We Collect
For all users:
-
Your full name, email address, and contact details
-
Account login credentials and multi-factor authentication codes (if applicable)
-
Payment information for in-app purchases (if applicable)
-
Device information, IP address, and usage statistics for system maintenance and audit purposes
-
Relationship to the baby (parent/guardian)
-
Baby’s name, gender
-
Audio recordings (heartbeat, voice messages)
For hospital-based use:
-
Baby’s identifiers (e.g., QR code, hospital ID), and postmenstrual age
Note: None of the data we collect is considered special category data under GDPR.
3. Purpose of Processing
Hospital-Based Use:
-
Enable your baby to hear parental audio (voice, heartbeat) in the hospital setting
-
Support neonatal care and hospital clinical programs
-
Maintain an audit trail of consent
Private Use:
-
Enable app functionality, audio recording, storage, and playback
-
Facilitate app updates and product improvements
4. Lawful Basis for Processing
Hospital-Based Use:
The Hospital (Controller) determines the lawful basis under Article 6 GDPR/UK GDPR, which will typically be:
-
Article 6(1)(e) (task carried out in the public interest), or
-
Article 6(1)(f) (legitimate interests), depending on the Hospital’s status.
Where the Hospital relies on consent, Incubeats collects and records such consent strictly on the Hospital’s behalf.
Private Use:
Incubeats acts as Controller and relies on Article 6(1)(a) (consent).
5. Sharing Your Data
Hospital-Based Use:
Your data will only be shared with the hospital you select during registration and, if applicable, with other participating hospitals if your baby is transferred.
Data will not be shared for marketing purposes.
Private Use:
Your data will not be shared with any hospital unless you explicitly choose to do so.
We do not sell, lease, or distribute your personal information without your permission, unless required by law.
6. Consent Collection and Withdrawal
By registering in the App and selecting your hospital, you provide explicit consent to the hospital for processing your personal data.
Consent is recorded by Incubeats on the hospital’s behalf.
You may withdraw consent at any time via the App or by contacting the hospital currently responsible for your baby’s care.
Withdrawal will stop further processing but does not affect processing prior to withdrawal.
7. Data Retention and Deletion
Hospital-Based Use:
Your data is stored according to the hospital’s instructions.
Private Use:
Your data is retained until you request account deletion.
Account deletion can be requested via the App: select “Delete my account”. Incubeats will aim to permanently delete your data within 7 days.
Backups will be purged within 30 days.
Retention periods are defined in our Retention Schedule (available via the App or on request).
8. Security Measures
We implement technical, physical, and managerial safeguards to protect your data against unauthorized access, disclosure, alteration, and destruction.
Access to personal data is restricted to authorized personnel only.
9. Transfers Between Hospitals
At the time of giving consent, the hospital selected during registration is the Data Controller.
If your baby is transferred to another hospital included in the list of participating hospitals, your consent covers the use of your personal data by the new hospital for the same purposes.
Any transfer of personal data between hospitals is a controller-to-controller disclosure initiated by the hospitals.
Incubeats, acting as Processor, will only facilitate secure transfer on the hospitals’ documented instructions and will keep transfer logs.
10. Your Rights
Under GDPR, you have the right to:
-
Access your personal data
-
Rectify any inaccuracies
-
Erase your data (where applicable)
-
Restrict processing
-
Object to processing
-
Data portability (where applicable)
-
Withdraw consent at any time
Requests can be made via the App or by contacting the hospital (for hospital-based use) or Incubeats (for private use) at general@incubeats.com.
You also have the right to lodge a complaint with a supervisory authority:
-
In the UK, this is the Information Commissioner’s Office (ICO).
-
For EU residents, you may contact your local data protection authority.
If we act as Processor (hospital use), we will promptly route your request to the relevant Hospital Controller.
11. Updates to this Privacy Policy
This Privacy Policy may be updated from time to time.
The latest version will be posted on our website and is accessible via the App.
12. Contact Information
Incubeats Tech Ltd
13 Chamberlains Gardens, Leighton Buzzard, LU7 3AP, England
Email: general@incubeats.com