Nerida Health — Privacy Notice
Version 1 · Effective 5 October 2026 · Permanent copy: https://neridahealth.com/en/legal/privacy-notice/v1/
Summary
- Who we are. Nerida Health is run by Nerida, Inc., a Delaware corporation, 2810 N Church St STE 89909, Wilmington, DE 19802. Privacy contact: privacy@neridahealth.com.
- What we hold. Your account details, the health records and messages you and your care team put in, files, sharing permissions, plan and payment status, device details for notifications, security and access records, and what you send to support.
- Why. To run the service you asked for, apply the permissions you set, run accounts and plans, help you, keep the service secure and meet our legal duties.
- What we never do. We do not sell your information, show advertising, use third-party trackers or use your information to train AI models.
- Who sees it. Only the people you or your clinician allow, our authorised staff where needed, and the service providers listed in section 5.
- Where. Our servers are in Frankfurt, Germany (Amazon Web Services). Some providers work in other countries, including the United States.
- How long. Account details: until 14 days after you close your account. Clinical records and messages: for as long as the treating clinician must legally keep them.
- Your rights. You can ask to see, correct, delete or take a copy of your information, and complain. Your rights never depend on paying.
- Accepting our Terms is not consent to any use of your health information. Where we need your consent, we ask for it separately.
1. Who is responsible
Operator: Nerida, Inc., a Delaware corporation, 2810 N Church St STE 89909, Wilmington, DE 19802; contact hello@neridahealth.com; privacy contact privacy@neridahealth.com. Our director works from Melbourne, Australia. We have not appointed a data protection officer.
We decide how accounts, security, billing and support work, so we are responsible for that information. Your clinician or clinic decides how your clinical records are used for your care; for that information, they are responsible and we process it on their behalf (in the United States, for a HIPAA covered entity, as its business associate). Information you record for yourself in your own health log is information we are responsible for. Your clinician may have their own privacy notice for the care they give you.
We offer accounts in the United States, Australia and Türkiye. If you join a waitlist from elsewhere, we use your email address only to tell you when the service becomes available to you, and you can ask us to remove it at any time. Our public website does not use analytics or marketing trackers.
2. Information we hold and where it comes from
| What | Examples | Where it comes from and why |
|---|---|---|
| Account and sign-in | Name, email, phone, date of birth, country, language, time zone, account type, sign-in and recovery details | You and the sign-in provider you choose; to create your account, check you are eligible and let you sign in safely |
| Health records and messages | History, health-log entries, forms, appointments, messages, care plans, attachments, rules your clinician writes | You, your clinician, a carer you allowed, or your clinician's assistant; to keep your records and coordinate your care |
| Relationships and permissions | Invitations, connections, carer and guardian relationships, their scope and end date, assistant permissions | The people involved; to decide who may see or do what |
| Clinician profile and documents | Profession, specialty, optional credential documents and who they are shared with | The clinician; to personalise the service and let them share documents with their own patients. We do not verify them |
| Plans and payments | Plan, currency, receipt reference, renewal, cancellation, refund and offer status | You, Stripe, Apple or Google; to sell plans and give you what you paid for. We never receive your full card number |
| Devices and delivery | Notification token, device type, email delivery status | Your device and our delivery providers; to send messages, reminders and security alerts you asked for |
| Security and usage records | IP address, request details, who accessed which record and when, errors, how features are used | Our systems; to keep the service secure, show you who has seen your records, fix problems and improve the product |
| Support and complaints | Your contact details, your message and anything you attach | You; to help you and handle requests and complaints |
Some of this can reveal health information even when it contains no diagnosis. If someone else enters information about you, they must have the right to do so. Some information is required to provide a function (for example, an email address to create an account); if you do not give it, we tell you which function cannot work. Optional information is marked as optional.
3. Why we use it, and on what basis
We use information to: provide the records and communication you ask for; apply connections and permissions; run accounts; sell plans; answer support and privacy requests; keep the service secure, audited and recoverable; and meet legal duties to keep or disclose information. We measure how features are used, ourselves, only to improve the product, and never using the content of your health records.
Our basis depends on the activity and on the law that applies to you: providing the contract you asked for (accounts, plans, the functions you use); our legal duties (tax and accounting records, valid legal requests); our legitimate interest in a secure, working service (security, fraud prevention, troubleshooting, product measurement), weighed against your rights; and your explicit consent where the law requires it for health information. Accepting the Terms is never consent to health processing. Where we rely on consent, you can withdraw it at any time, and saying no to something optional never takes away your rights or the parts of the service that do not need it.
We do not diagnose, triage or recommend treatment. Any patient-specific rules are written by your clinician.
4. Sharing within your care circle, and children
Your records are shared only through the relationships and permissions you or your clinician set up. Each is separate: a clinician connection does not give an assistant access, and a carer relationship gives only the access it lists. Our administrators access records only for a specific lawful reason, and that access is recorded. Credential documents a clinician shares are visible only to their own connected patients, never to assistants or carers.
People under 18 cannot create their own account. A clinician can keep a record for a child who is their patient, managed by a recorded parent or guardian, where the law allows. When a child reaches the age at which the law gives them control of their own health information, their rights apply.
5. Who receives information and where
| Recipient | What they handle | Role and location |
|---|---|---|
| Your care circle | The records, messages and profile details you or your clinician allow | Your clinician or clinic is responsible for their care records |
| Amazon Web Services (servers, database, files, encryption keys, backups) | All service data | Processes for us; Frankfurt, Germany |
| Amazon Cognito | Sign-in details and security events | Processes for us; Frankfurt, Germany |
| Amazon SES | Email address and the email we send you | Processes for us; Frankfurt, Germany. Our emails do not contain your health records |
| Amazon CloudFront | Network details of each request while it is in transit | Processes for us; edge locations worldwide, origin in Frankfurt |
| Stripe | Web purchases: name, email, plan and payment details | Processes payments; also responsible for its own fraud and legal duties; United States and other countries |
| Apple and Google (app stores) | App purchases, renewals and refunds | Responsible for their own store; United States and other countries |
| Apple, Google, Facebook (Meta) and Microsoft (sign-in), if you choose one | That you are signing in to Nerida Health; we send them nothing else. From them we receive the sign-in confirmation and the details you agree to share | Responsible for their own sign-in service; United States and other countries |
| Apple, Google and Expo (notifications) | Notification token and delivery details; notifications do not show health details | Process for us; United States |
| Google Workspace (support email) | Messages you send to support and their attachments | Processes for us; United States and other countries |
| Our authorised staff | Only what a support, security or legal task needs | Australia; every access to records is recorded |
| Authorities | Only what a valid legal request or duty requires | We check each request and disclose no more than required |
We add a provider to this list before it receives personal information. Public registers you check yourself are not our providers.
6. International transfers
Our servers are in Germany, our staff work in Australia, and some providers work in the United States and other countries. When information moves between countries, we use the safeguards the applicable law requires, such as contracts with the provider that protect your information. You can ask us for a copy of the relevant safeguards at privacy@neridahealth.com.
7. Advertising, measurement, research and AI
We do not show advertising, use third-party trackers, sell personal information or share it for advertising. We measure how features are used ourselves, without the content of health records, only to improve the product, and keep those measurements for no more than 24 months. We do not use your information to train AI models. If we ever offer research, it will be optional, with its own information and consent.
8. Security and your access history
We encrypt information in transit and at rest, require strong sign-in, limit every person's access to what their role and permissions allow, and record every read and change of health records. No system is perfectly secure; if a breach affects you, we will tell you and the relevant authorities as the law requires. The access history in the app shows who viewed or changed your records. It does not show automated system tasks, and it is not a legal "accounting of disclosures"; you can ask us for that separately.
9. How long we keep information
- Account and sign-in details: when you close your account, we deactivate it at once, give you 14 days to restore it, and erase your sign-in credentials on day 14. An account that never connected with anyone and has no private backup can be deleted immediately.
- Private backup: on day 14 we schedule the destruction of the key that protects it, which makes the backup unreadable.
- Clinical records, messages and their audit records: for as long as the treating clinician's legal record-keeping duty requires where they practise, often seven years or more after the last care, and longer for children. Where no retention period for your jurisdiction has been set, we do not delete them automatically; that protects records the law may require to be kept, and you can still ask for deletion.
- Messages: users cannot delete them; after an account is deleted, its messages show "Deleted account" as the sender.
- Billing records: for as long as tax and accounting law requires, generally up to seven years.
- Security logs: for as long as needed to protect the service and investigate incidents, generally no more than two years.
- Support messages: up to three years after the matter is closed.
When we no longer need information, we delete it or remove what identifies you. A legal hold must name its legal authority, scope, keeper and end or review date; a clinician's approval alone does not end it. If we keep something you asked us to delete, we tell you the legal reason and how to challenge it.
10. Your rights and how to use them
Depending on where you live, you can ask to: know whether we hold your information and get a copy; correct it; delete it; restrict or object to its use; take it to another service; withdraw consent; and not be subject to a decision made only by automated means that significantly affects you (we make no such decisions). Clinical records are corrected by adding a correction; you can still challenge inaccurate information.
Contact privacy@neridahealth.com or write to 2810 N Church St STE 89909, Wilmington, DE 19802. We ask only for what we need to confirm your identity or authority. A carer can act for someone else only with legal authority. Your rights do not depend on a paid plan, an in-app limit or a clinician's approval. We will acknowledge your request, answer within the time the law sets, and explain any refusal and how to challenge it. If a clinician is responsible for the record, we tell you and help you reach them. For urgent health needs, contact a clinician or emergency service, not us.
11. Changes to this notice
This notice always lives at the permanent address above, with its effective date. We tell you about important changes before they take effect. A new use of your information that needs your consent will ask for it first.
United States
HIPAA. HIPAA applies when we handle protected health information for a covered entity, such as your clinician, under a Business Associate Agreement. For information you keep in your own account, other laws apply, including the FTC Health Breach Notification Rule, which requires us to notify you, the FTC and in some cases the media of a breach.
Consumer health data (including Washington and Nevada). We collect consumer health data — the records, health-log entries, messages, files and appointments described in section 2, and account, device and usage information linked to them — only to provide the service you asked for, or with your separate consent. We share it only with the recipients in section 5, for the purposes in section 3, and we have no affiliates that receive it. We do not sell it, and we do not use location to target people near health facilities. You can ask whether we collect or share your consumer health data and with whom, withdraw consent and ask us to delete it, at privacy@neridahealth.com. If we refuse, you can appeal by replying to our decision; we answer an appeal within 45 days. If your appeal is refused, you can complain to the Washington or Nevada Attorney General.
Other state rights. If you live in a state that gives you further privacy rights, you can use them the same way. We do not sell or "share" personal information for advertising, so there is nothing to opt out of.
Australia
We handle personal information under the Australian Privacy Principles and the health-records laws of the states and territories. Health information is sensitive information: we collect it only when it is needed for the service and with your consent or another lawful ground. Overseas recipients are described in sections 5 and 6 (mainly Germany and the United States); we remain accountable for how they handle it. You can ask to access or correct your information through section 10; we answer within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner. Complaints about clinical care can go to your state or territory health complaints body or Ahpra.
Türkiye — information notice under the Personal Data Protection Law No. 6698 (KVKK)
This notice is given under Article 10 of Law No. 6698. It does not ask for your consent. If explicit consent is needed for a purpose, we ask for it separately, after giving you this information.
Data controller. Nerida, Inc., 2810 N Church St STE 89909, Wilmington, DE 19802, privacy@neridahealth.com, for the platform activities we decide (accounts, security, billing, support and your own health log). For the clinical records your clinician keeps, your clinician is the data controller and we process them on their behalf.
How we collect it. Electronically, through sign-up, sign-in, records, forms, files, messages, connections, purchases, our systems and support, from you and from the people and providers described in sections 2 and 5.
Purposes and legal grounds.
| Purpose | Legal ground |
|---|---|
| Creating and running your account and plan | Article 5(2)(c): necessary for the contract |
| Tax, accounting and legal requests | Article 5(2)(ç): our legal obligation |
| Security, fraud prevention, troubleshooting and product measurement without health content | Article 5(2)(f): our legitimate interest, without harming your fundamental rights |
| Your own health log and other health information we process for our own purposes | Article 6(2): your explicit consent, requested separately |
| Clinical records kept by your clinician | Your clinician's ground as data controller, including Article 6(3) for persons under a duty of confidentiality |
Who we transfer it to. Within Türkiye, to your care circle as you allow, and to authorities only where the law requires (Article 8). Abroad: to the providers in section 5, mainly in Germany and the United States. We transfer data abroad only on a ground permitted by Article 9: the standard contracts announced by the Personal Data Protection Board, notified to the Personal Data Protection Authority within five business days of signing, or another ground in Article 9 for occasional transfers.
How long. As set out in section 9. When the reason to process ends, we delete, destroy or anonymise the data under Article 7 and our retention and destruction policy.
Your rights (Article 11). You can learn whether your data is processed and obtain information about it; learn the purpose and whether it is used for that purpose; know the recipients in Türkiye and abroad; ask for correction, deletion or destruction and for recipients to be told; object to a result against you arising only from automated analysis; and claim compensation for damage from unlawful processing.
How to apply. Send your request in writing to 2810 N Church St STE 89909, Wilmington, DE 19802, or by email from the address registered in your account to privacy@neridahealth.com, as the Communiqué on the Procedures for Applications to the Data Controller allows. We answer free of charge within 30 days at the latest, in writing or electronically. If we refuse, our answer is insufficient or we do not answer in time, you can complain to the Personal Data Protection Board within 30 days of our answer and in any case within 60 days of your application.