Global Privacy Notice
January 1, 2026
Primary controller: Higia, Inc. (operating under the commercial brand "Eden").
Data Protection Officer (DPO) contact: legal@edenmed.com
1. PREAMBLE
1.1 This Global Privacy Notice (the "Notice") establishes Eden's Universal Privacy & Data Standard (EUPD). This instrument is not an exercise in minimum compliance: it is a statement of principles that deliberately and permanently adopts the highest level of personal data protection recognized in any jurisdiction where Eden operates or may come to operate.
1.2 The EUPD is built on a single axiom: if a local law, present or future, grants the data subject a broader protection than that contained in this Notice, such protection is automatically incorporated into the processing that Eden carries out in that jurisdiction, without the need to amend this document. We refer to this mechanism as the Automatic Maximum Protection Clause (MPA).
1.3 Nevertheless, when Eden identifies that a jurisdiction imposes a more demanding standard than the global EUPD floor, Eden will raise that floor for all jurisdictions, unless doing so is technically or legally unfeasible.
1.4 This Notice applies in all jurisdictions where Eden, through Higia, Inc. or any of its subsidiaries, offers products or services, or carries out any personal data processing operation.
2. IDENTITY OF THE CONTROLLER AND RELATED ENTITIES
2.1 The primary controller of personal data processing is Higia, Inc., domiciled at 300 Delaware Ave., Suite 210 #215, Wilmington, DE 19801, United States of America. The email address of the Data Protection Officer (DPO) is legal@edenmed.com.
2.2 Higia, Inc. operates under the commercial brand "Eden" and has the following subsidiaries, each of which may act as controller or processor depending on the operation in question:
2.2.1 Higia, Inc. — Jurisdiction: United States (Delaware). Domicile: 300 Delaware Ave., Suite 210 #215, Wilmington, DE 19801, United States of America. Role: Parent — Primary controller.
2.2.2 Eva Health, S.A.P.I. de C.V. — Jurisdiction: Mexico. Domicile: Av. Horacio 632, Piso 1, Polanco IV Sección, Miguel Hidalgo, 11550, Mexico City, Mexico. Role: Subsidiary — Controller or Processor.
2.2.3 United Surgical Importação e Exportação Ltda. — Jurisdiction: Brazil. Domicile: Av. Ordem e Progresso 157, Cj. 1713, Várzea da Barra Funda, São Paulo – SP, 01141-030, Brazil. Role: Subsidiary — Controller or Processor.
2.2.4 Eden Colombia Latinoamérica S.A.S. — Jurisdiction: Colombia. Domicile: Calle 96 # 10-29, Oficina 502, Bogotá D.C., Colombia. Role: Subsidiary — Controller or Processor.
2.3 In countries where Eden does not have an incorporated subsidiary (including, by way of illustration but not limitation, Peru, Ecuador, Chile and other jurisdictions in Latin America, the European Union and the rest of the world), services are provided by one of the aforementioned subsidiaries, acting as controller under the instructions and policies of Higia, Inc.
2.4 In the European Union and the European Economic Area, where Higia, Inc. or any of its subsidiaries not established in the EU acts as controller of the data of individuals located in that territory, Eden will designate a representative in accordance with Article 27 of Regulation (EU) 2016/679 (GDPR — General Data Protection Regulation). The representative's contact details will be published at legal.edenmed.com and communicated to the competent supervisory authority.
3. AUTOMATIC MAXIMUM PROTECTION CLAUSE (MPA)
This Notice incorporates the following continuous-update mechanism:
3.1 Automatic incorporation. If, in any jurisdiction where Eden operates or comes to operate, a law, regulation, judicial decision, or data protection authority criterion establishes a right, guarantee, security standard, or transparency obligation more favorable to the data subject than that provided in this Notice, such provision is deemed automatically incorporated into the processing that Eden carries out in that jurisdiction, without the need for a formal amendment to this document.
3.2 Non-regression. The protection standards contained in this Notice constitute an irreducible minimum floor. No local provision offering less protection than this Notice will reduce the rights recognized herein.
3.3 Global elevation. When the review of the Regulatory Correspondence Annex identifies that a jurisdiction imposes a more demanding standard than the global EUPD floor, Eden will assess the feasibility of raising that floor for all jurisdictions. If the elevation is feasible, it will be incorporated in the next version of the Notice.
3.4 Proactive transparency. Eden will publish and keep updated a Regulatory Correspondence Annex on its website (legal.edenmed.com), indicating, for each jurisdiction, the applicable rules and any additional right the data subject may exercise under local law. This Annex is binding on Eden and its subsidiaries.
3.5 Periodic review. Without prejudice to automatic incorporation, Eden will carry out semiannual reviews of the global regulatory landscape to update the Regulatory Correspondence Annex and, where applicable, raise the standards of this Notice.
4. SCOPE OF APPLICATION
4.1 Territorial scope. This Notice applies to every natural person (the "Data Subject") whose personal data is processed by Eden, regardless of: (a) the geographic location of the Data Subject; (b) the country from which the services are accessed; (c) the nationality or residence of the Data Subject; and (d) the Eden Group entity acting as controller or processor.
4.2 Material scope. This Notice applies to all personal data processing carried out by Eden, whether automated, partially automated, or non-automated, including operations carried out through Eden Suite and each of its modules:
4.2.1 Eden PACS (Picture Archiving and Communication System): storage and management of DICOM (Digital Imaging and Communications in Medicine) images.
4.2.2 Eden Management (RIS — Radiology Information System): workflows, schedules, and reports.
4.2.3 Eden Intelligence: analytics and metrics.
4.2.4 Eden Creator: assistant for drafting conclusions; does not generate diagnoses.
4.2.5 AI Report: an agent that transforms dictation into structured drafts; requires a physician's signature for release.
4.2.6 Eden AI: diagnostic support through artificial intelligence models applied to DICOM studies; does not replace clinical judgment.
4.2.7 Eden Portal: web portal with a DICOM viewer for patients.
5. DEFINITIONS
For the purposes of this Notice, the terms defined below shall have the meaning indicated. Where a term is not defined here, the definition given to it by the applicable law in the relevant jurisdiction shall apply.
5.1 Data Protection Authority: any public body with competence over personal data protection in a given jurisdiction (for example, the competent authority in Mexico, the ANPD in Brazil, the SIC in Colombia, the ANPDP in Peru, the SPDP in Ecuador, the Personal Data Protection Agency in Chile, the AEPD in Spain, the CNIL in France, among others).
5.2 Client: a natural or legal person who contracts Eden's products or services, including Eden Suite, through a service agreement. The Client acts as joint controller with respect to the personal data it transmits to Eden, and as processor with respect to the personal data it receives from Eden.
5.3 Consent: a free, specific, informed, and unambiguous expression of the Data Subject's will, by which they accept the processing of their personal data. In the case of sensitive personal data, consent must also be explicit.
5.4 Personal Data: any information relating to an identified or identifiable natural person. A person is considered identifiable if their identity can be determined, directly or indirectly, including through location information and online identification.
5.5 Sensitive Personal Data: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, sex life, or sexual orientation of the Data Subject. For Eden's purposes, every DICOM medical image and all clinical data associated with a patient are considered sensitive personal data.
5.6 Data Protection Officer (DPO): a person designated by Eden to oversee compliance with personal data protection obligations, to serve as a point of contact for Data Subjects and Data Protection Authorities, and to advise the Eden Group on the matter.
5.7 Dissociation (Anonymization): a technical procedure by which personal data can no longer be associated with the Data Subject in an irreversible manner, such that the resulting information does not permit identification.
5.8 Eden / Eden Group: Higia, Inc. and any of its subsidiaries, affiliates, or related entities that participate in the processing of personal data.
5.9 Processor: a natural or legal person who processes personal data on behalf of and under the instructions of the Controller.
5.10 Data Protection Impact Assessment (DPIA): a systematic analysis of the risks that a processing operation may pose to the rights and freedoms of Data Subjects, including measures to mitigate such risks. Also known as EIPD (Evaluación de Impacto en Protección de Datos) or RIPD (Relatório de Impacto à Proteção de Dados).
5.11 Security Incident: any event that compromises the confidentiality, integrity, or availability of personal data, including unauthorized access, loss, destruction, alteration, or improper disclosure.
5.12 Controller: a natural or legal person who determines the purposes and means of the processing of personal data. In Eden's context, the Controller varies depending on the legal relationship and applicable jurisdiction, as described in Clause 2 of this Notice.
5.13 High-Risk AI System: an artificial intelligence system classified as high-risk under Regulation (EU) 2024/1689 (AI Act) or other applicable artificial intelligence legislation. Eden AI may be classified as such when operating on health data.
5.14 Data Subject: the natural person to whom the personal data being processed corresponds.
5.15 Processing: any operation or set of operations performed on personal data, by any means, including collection, recording, organization, structuring, storage, adaptation, modification, extraction, consultation, use, communication by transmission, dissemination, comparison, interconnection, restriction, erasure, and destruction.
5.16 User: a natural person who uses Eden Suite through an Eden Client, without a direct contractual relationship with Eden. The User includes patients, medical staff, and administrative staff of the Client.
6. GUIDING PRINCIPLES
All personal data processing carried out by Eden is governed by the following principles, which constitute binding obligations for all entities of the Eden Group and prevail over any restrictive interpretation:
6.1 Lawfulness, fairness, and transparency. All processing will have a valid legal basis, be carried out in good faith, and be communicated to the Data Subject in a clear, accessible, and comprehensible manner.
6.2 Purpose limitation. Personal data will be collected for specified, explicit, and legitimate purposes, and will not be further processed in a manner incompatible with those purposes.
6.3 Data minimization. Only personal data that is adequate, relevant, and strictly necessary for the purposes of the processing will be collected.
6.4 Accuracy. Personal data will be accurate and, where necessary, kept up to date. Reasonable measures will be taken to erase or rectify inaccurate data without delay.
6.5 Storage limitation. Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, unless a legal obligation requires a longer retention period.
6.6 Integrity and confidentiality. Personal data will be processed in a manner that ensures its security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
6.7 Accountability. Eden will be able to demonstrate compliance with all the foregoing principles and with the obligations arising from this Notice and applicable law.
6.8 Privacy by design and by default. Personal data protection will be integrated into the design of all Eden products, services, and processes. The default configuration will always be the most protective of the Data Subject's privacy. In the development of software and information systems that process personal data, Eden will adopt DevPrivOps and DevSecOps practices, integrating privacy and security risk management from the earliest stages of the development lifecycle.
6.9 Non-discrimination. No Data Subject will suffer adverse consequences for exercising their personal data protection rights.
6.10 Surviving confidentiality. The duty of secrecy and confidentiality over the Data Subject's personal data subsists even after the relationship between Eden and the Data Subject, or between Eden and the Client, has ended.
7. CATEGORIES OF DATA SUBJECTS, PERSONAL DATA, AND PURPOSES
Eden processes personal data of the categories of Data Subjects described in this clause. For each category, the types of data collected, the primary purposes (necessary for the legal relationship), and the secondary purposes (not necessary; subject to objection or withdrawal of consent) are detailed. The categories are: (A) Browsing Users; (B) Clients; (B.1) Client Joint Controllership; (C) Eden Suite Users; (D) Candidates; (E) Employees; (F) Subscribers; and (G) Suppliers and Potential Suppliers.
7.1 Browsing Users. These are Data Subjects who browse the website edenmed.com without maintaining a contractual relationship with Eden.
7.1.1 Data collected: (a) IP address (anonymized for analytics purposes); (b) browsing data: pages visited, time spent, navigation sequence, and clicks made; (c) technical device data: browser type, operating system, screen resolution, and language; and (d) data obtained through cookies, web beacons, and JavaScript, subject to the Data Subject's preferences (see Clause 13).
7.1.2 Primary purposes: (a) to ensure the technical functioning and security of the website; and (b) to detect and prevent fraudulent activity or threats to the portal.
7.1.3 Secondary purposes: (a) statistical and geolocation analysis to improve the browsing experience; and (b) content personalization.
7.2 Clients. These are Data Subjects (natural persons or representatives of legal entities) who contract Eden's products or services through a service agreement.
7.2.1 Data collected: (a) identification data: full name, date and place of birth, age, gender, nationality, telephone number, email, copy of official identification (passport or other document), and proof of address; (b) for legal entities: incorporation deed, tax identification (RFC, CNPJ, NIT, or equivalent), and details of the legal representative; (c) financial data: bank accounts, CLABE, or other financial data necessary for the commercial relationship; and (d) location data: tax and commercial address.
7.2.2 Primary purposes: (a) to verify the identity and existence of the Client; (b) to enter into, perform, and develop the services agreement and its accessory instruments; (c) to comply with legal, tax, and regulatory obligations; and (d) to create and manage the databases necessary to provide the service.
7.2.3 Secondary purposes: (a) to send information about Eden's products, services, promotions, or events; and (b) to conduct satisfaction surveys, market analysis, and statistical studies.
7.3 Client Joint Controllership. Eden declares that, in order to provide its services, Clients will transmit to Eden the personal data of third parties under their custody, including data of patients, medical staff, treating physicians, and persons authorized to receive medical information. Consequently:
7.3.1 The Client undertakes to obtain the consent of the Data Subject before transmitting their data to Eden, in accordance with the applicable law in its jurisdiction.
7.3.2 The Client undertakes to establish the necessary legal documentation with the Data Subject (including employment contracts, service agreements, its own privacy notices, and informed consents, as applicable).
7.3.3 The Client undertakes to implement its own administrative, technical, and physical security measures to protect the personal data it manages.
7.3.4 The Client acts as joint controller with respect to the data it transmits to Eden, and as processor with respect to the data it receives from Eden.
7.3.5 Eden, in turn, acts as controller with respect to the data stored on its servers in accordance with the contractual relationship with the Client.
7.4 Eden Suite Users. These are Data Subjects (natural persons) who use Eden Suite through Eden's Clients, without a direct contractual relationship with Eden. This category includes patients, medical staff, radiologists, and administrative staff of the Client.
7.4.1 Data collected: (a) of patients: identification number (hospital record or other), name, sex, date of birth, marital status, nationality, contact details, medical history, information on diagnoses and procedures, DICOM radiological images and associated reports, and results of examinations and laboratory tests; (b) of health professionals: identification data, professional registration data (professional license, CRM, or equivalent), training and specialization data, and system access credentials; (c) of system use: access logs, records of transactions performed, and usage preferences and settings; and (d) of security: electronic security records, access attempts, and authentication data.
7.4.2 Primary purposes: (a) to provide the health services contracted by the Client, including storage, management, and viewing of medical images and reports; (b) to manage the patient's electronic health record; (c) to facilitate clinical communication among health professionals; (d) to ensure the security, integrity, and traceability of medical information; and (e) to comply with legal and regulatory obligations of the health sector.
7.4.3 Secondary purposes: (a) improvement of the quality and experience of Eden Suite services; and (b) research and development of new functionalities, always with anonymized data or with the explicit consent of the Data Subject.
7.4.4 Note on ownership. The data stored by the Client on Eden's servers is the property of the Client or the User, respectively, in accordance with the applicable legal-contractual relationship. The User of a Client must first refer to the privacy notice provided by the Client that contracted Eden's services.
7.4.5 Data generated by AI systems. When a DICOM study is processed by Eden AI or AI Report, the processing metadata (date, model version, type of analysis, and suggested result) are considered personal data associated with the patient and are subject to the same protections as the original images. The Data Subject has the right to know that their data was processed by an artificial intelligence system and to obtain meaningful information about the logic of the processing.
7.5 Candidates. These are Data Subjects who participate in Eden's selection and recruitment processes.
7.5.1 Data collected: (a) identification data: name, address, contact details, and identity document; (b) location data: address; and (c) professional and academic data: educational background, work experience, personal and professional references, and certifications.
7.5.2 Primary purposes: (a) to verify the Candidate's identity; (b) to assess their professional profile and suitability for the position; (c) to establish contact during the selection process; and (d) to create and maintain internal candidate databases.
7.6 Employees. These are Data Subjects who perform personal, subordinate, and remunerated work for Eden, in any jurisdiction.
7.6.1 Data collected: (a) identification data: name, address, telephone, personal and institutional email, marital status, signature, photograph, tax identification, social security number or equivalent, and data of family members and beneficiaries; (b) financial data: bank account and information necessary for payroll and tax compliance; (c) employment data: employment contract, incidents, evaluations, training, and payroll data; (d) academic data: degrees, professional licenses, and certifications; (e) biometric data: fingerprint for access control to facilities (where applicable, with explicit consent); and (f) voice data: recording of calls made through corporate applications, for quality purposes (where applicable, with prior notice).
7.6.2 Primary purposes: (a) to enter into and perform the employment contract and its accessory instruments; (b) to comply with labor, tax, and social security obligations; (c) to manage the employment relationship, including payroll, benefits, training, and evaluation; and (d) to ensure the security of facilities and information systems.
7.7 Subscribers. These are Data Subjects who voluntarily subscribe to Eden's communications (newsletters, commercial information, events).
7.7.1 Data collected: name, position, company, industry, email, and telephone number.
7.7.2 Purposes: (a) sending commercial communications, news, events, and promotions related to Eden; and (b) conducting satisfaction surveys and market studies.
7.7.3 The Subscriber may withdraw their consent and unsubscribe at any time through the unsubscribe link included in each communication or by contacting legal@edenmed.com.
7.8 Suppliers and Potential Suppliers.
7.8.1 Data collected: (a) identification of the company and its representatives; (b) internet and social media presence; and (c) corporate background, reputation, permits, licenses, and certifications.
7.8.2 Primary purposes: (a) to verify the identity and existence of the supplier; (b) to assess the viability of the commercial relationship; and (c) to enter into and perform service agreements.
8. LEGAL BASES FOR PROCESSING
8.1 Eden bases each processing operation on at least one of the following legal bases, in accordance with the applicable law in each jurisdiction:
8.1.1 Consent. A free, specific, informed, and unambiguous expression of the Data Subject's will; explicit for sensitive data. Example: newsletter subscription; processing of employees' biometric data.
8.1.2 Contractual performance. Processing is necessary to enter into or perform a contract with the Data Subject. Example: management of the Client's account; provision of Eden Suite.
8.1.3 Legal obligation. Processing is required by an applicable legal rule. Example: retention of tax records; reporting to health authorities.
8.1.4 Legitimate interest. Processing is necessary to satisfy the legitimate interests of Eden or a third party, provided the rights of the Data Subject do not prevail. Eden documents and balances such interests. Example: network and system security; fraud prevention.
8.1.5 Vital interest. Processing is necessary to protect the life of the Data Subject or another natural person. Example: medical emergencies in the context of Eden Suite.
8.1.6 Public interest or exercise of authority. Processing is necessary for the performance of a task carried out in the public interest. Example: reporting of communicable diseases to health authorities.
8.1.7 Protection of health. In jurisdictions that recognize it (Brazil, LGPD art. 11), the processing of health data for the protection of the Data Subject's health. Example: storage and management of DICOM medical images.
8.1.8 Sectoral regulatory compliance. Processing is necessary to comply with sectoral health regulation (HIPAA Privacy Rule, NOM-004-SSA3, CFM rules, among others). Example: Business Associate Agreements in the U.S.; retention of clinical records in Mexico.
8.2 Eden applies the most protective legal basis available in each jurisdiction. Where there is doubt about the applicable legal basis, Eden will opt to request the Data Subject's consent.
9. RIGHTS OF THE DATA SUBJECT
Eden recognizes and guarantees to every Data Subject, regardless of jurisdiction, the exercise of the following rights. This catalog constitutes the union of all rights recognized by the applicable laws and, by virtue of the Automatic Maximum Protection Clause, extends equally to all Data Subjects:
9.1 Access. To obtain confirmation of whether Eden processes their personal data and, where applicable, to access it, including information about the purposes of the processing, the categories of data, the recipients, the retention periods, and the source of the data.
9.2 Rectification. To request the correction of inaccurate or incomplete personal data.
9.3 Cancellation or erasure (right to be forgotten). To request the deletion of their personal data when it is no longer necessary for the purposes for which it was collected, when they withdraw their consent, when they object to the processing, when the data has been unlawfully processed, or when a legal obligation must be fulfilled.
9.4 Objection. To object to the processing of their personal data at any time, on grounds relating to their particular situation. Eden will cease the processing unless it demonstrates compelling legitimate grounds.
9.5 Restriction of processing (blocking). To request that Eden restrict the processing of their personal data while the accuracy of the data, the lawfulness of the processing, or the balancing of legitimate interests is verified.
9.6 Portability. To receive their personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller without hindrance.
9.7 Not to be subject to automated decisions. Not to be subject to a decision based solely on the automated processing of their data, including profiling, that produces legal effects or significantly affects them. Eden AI and AI Report generate results that always require review and validation by a medical professional; in no case is a clinical decision adopted on an exclusively automated basis.
9.8 Withdrawal of consent. To withdraw their consent at any time, without affecting the lawfulness of the prior processing. Withdrawal will be as simple as granting consent.
9.9 Information on transfers. To know to which third parties their personal data has been transferred and the applicable safeguards.
9.10 Non-discrimination. Not to suffer retaliation, penalty, or degradation of service for exercising any of the rights recognized herein.
9.11 Complaint before an authority. To file a complaint with the competent Data Protection Authority in their jurisdiction, without prejudice to any other administrative or judicial remedy.
9.12 Confirmation of the existence of processing. To obtain confirmation of whether or not Eden processes their personal data (autonomous right recognized by Brazil's LGPD).
9.13 Information on the possibility of not consenting. To be informed about the possibility of not granting their consent and about the consequences of refusal (autonomous right recognized by Brazil's LGPD).
9.14 Erasure of data processed with consent. To request the deletion of personal data processed on the basis of their consent, even when the processing is lawful (autonomous right recognized by Brazil's LGPD).
9.15 Free consultation. To consult their personal data free of charge at least once each calendar month and whenever there are substantial modifications to the processing policies (recognized by Colombia's Law 1581 of 2012 and analogous rules).
9.16 Compensation. A Data Subject who is harmed as a result of non-compliance with applicable law or this Notice has the right to obtain the corresponding compensation in accordance with the law (recognized by Article 25 of Peru's Law 29733; extensible to all jurisdictions where local law permits).
9.17 Prevention of disclosure. The Data Subject has the right to prevent their personal data from being supplied to third parties, especially when this affects their fundamental rights (recognized by Article 21 of Peru's Law 29733).
9.18 Habeas data. In jurisdictions where a constitutional habeas data action exists (Ecuador, Peru, Brazil, Colombia, among others), the Data Subject may resort directly to the constitutional remedy for the protection of their personal data, independently of the administrative route. Eden recognizes and respects this right and will cooperate with the judicial authorities hearing such actions.
9.19 Procedure for exercising rights.
9.19.1 The Data Subject may exercise any of their rights by sending a request to the email of the Data Protection Officer: legal@edenmed.com. The request must contain, at a minimum: (a) the full name of the Data Subject and a means to receive notifications (email or postal address); (b) documents evidencing their identity or, where applicable, the legal representation of the Data Subject; (c) a clear description of the right they wish to exercise and of the personal data involved; and (d) any other information that facilitates locating the personal data.
9.19.2 Eden will respond to the request within a maximum period of ten (10) business days from receipt of the complete request. Where the complexity or volume of requests justifies it, this period may be extended by an additional period of ten (10) business days, with prior notice to the Data Subject. In Peru, the response period will be eight (8) business days in accordance with the local legislation in force.
9.19.3 Users of Clients. Where the Data Subject is a User who accesses Eden Suite through a Client, the request to exercise rights must be directed in the first instance to the Client (the health service provider) through which the data was collected. Eden will cooperate with the Client to respond to the request.
10. PROCESSING OF SENSITIVE PERSONAL DATA
10.1 Given the nature of Eden's services in the health technology (healthtech) sector, Eden processes the following categories of sensitive personal data: (a) health-related data: medical history, diagnoses, procedures, DICOM radiological images, examination results, and medical reports; (b) biometric data: fingerprint (for employee access control, where applicable); (c) data that may reveal racial or ethnic origin, when it forms part of the patient's medical history; and (d) data generated by AI systems: metadata from the processing of DICOM studies by Eden AI or AI Report, including suggested results, which are classified as sensitive data due to their direct association with the Data Subject's health status.
10.2 The processing of sensitive personal data will be carried out only when at least one of the following conditions is met: (a) the Data Subject has given their explicit consent, having been clearly and specifically informed of the purposes; (b) the processing is necessary for the provision of health services, including preventive medicine, medical diagnosis, and management of health services; (c) the processing is required by a legal or regulatory obligation; (d) the processing is necessary to protect the life or physical integrity of the Data Subject or another person, when the Data Subject cannot give consent; or (e) the processing is carried out with data that has been manifestly made public by the Data Subject.
10.3 In any case, Eden will apply reinforced security measures for the processing of sensitive personal data, including encryption in transit and at rest, role-based access controls, and detailed audit logs.
11. PROCESSING OF DATA OF CHILDREN AND ADOLESCENTS
Eden recognizes that, in the context of health services, it may be necessary to process the personal data of minors. The processing of such data will be governed by the following rules:
11.1 Processing will always be carried out in the best interests of the minor.
11.2 The consent of the minor's parent, guardian, or legal representative will be required, unless a legal exception permits otherwise.
11.3 Eden will consider as a minor any person under eighteen (18) years of age, applying the most protective threshold among the laws of the jurisdictions where it operates.
11.4 The data of minors will only be collected when strictly necessary for the provision of health services.
11.5 Eden will not direct advertising or commercial communications to minors.
11.6 The website edenmed.com is intended for persons over eighteen (18) years of age. Minors should not use it without the supervision of a legal representative.
12. INTERNATIONAL DATA TRANSFERS
Since Eden operates through entities in multiple jurisdictions and uses cloud infrastructure, personal data may be transferred to countries other than the one where it was collected. Eden guarantees that every international transfer will be carried out with the following safeguards:
12.1 Safeguards for transfers.
12.1.1 Standard Contractual Clauses (SCCs). Eden will use contractual clauses approved by the competent authority (including the European Commission's SCCs) to ensure an adequate level of protection.
12.1.2 Binding Corporate Rules (BCRs). Intra-group transfers will be governed by internal policies that ensure a level of protection equivalent to that of this Notice.
12.1.3 Adequacy decisions. Where the competent authority has recognized that the destination country offers an adequate level of protection, the transfer will be carried out on the basis of that decision.
12.1.4 Explicit consent. Where none of the above safeguards is applicable, Eden will request the explicit consent of the Data Subject, informing them of the specific risks of the transfer.
12.2 Sub-processors. Eden may use sub-processors (including cloud infrastructure providers such as Amazon Web Services, Inc.) for the storage and processing of data. Eden guarantees that every sub-processor will be subject to contractual obligations equivalent to those contained in this Notice, will undergo a prior risk assessment, and will maintain an up-to-date register of sub-processors available for consultation.
12.3 Representative in the European Union. In accordance with Article 27 of the GDPR, where Higia, Inc. or any subsidiary not established in the EU acts as controller of the data of individuals located in the European Union or the European Economic Area, Eden will designate a representative established in a member state. The representative will serve as an additional point of contact for supervisory authorities and Data Subjects in the EU. The representative's contact details will be published at legal.edenmed.com.
12.4 Business Associate Agreements (BAA) in the United States. Where Eden provides services to entities qualified as a "covered entity" under the U.S. Health Insurance Portability and Accountability Act (HIPAA), Eden will enter into a Business Associate Agreement (BAA) in accordance with the requirements of the HIPAA Privacy Rule (45 CFR § 164.502(e)) and the HIPAA Security Rule (45 CFR §§ 164.308, 164.310, 164.312). The BAA will establish Eden's obligations as a "business associate," including the limitations on the use and disclosure of Protected Health Information (PHI).
13. COOKIES, WEB BEACONS, AND TRACKING TECHNOLOGIES
13.1 Eden uses cookies and similar technologies on its website and applications for the following purposes:
13.1.1 Strictly necessary cookies. Purpose: technical functioning of the site, security, and authentication. Duration: session. Legal basis: legitimate interest or technical necessity.
13.1.2 Performance or analytics cookies. Purpose: usage analysis, aggregate statistics, and service improvement. Duration: up to 24 months. Legal basis: consent.
13.1.3 Functionality cookies. Purpose: to remember the Data Subject's preferences (language, settings). Duration: up to 12 months. Legal basis: consent.
13.1.4 Advertising or marketing cookies. Purpose: content and advertising personalization. Duration: up to 12 months. Legal basis: consent.
13.2 Upon accessing Eden's website, the Data Subject will be informed through a visible banner about the use of cookies and will be able to manage their preferences. Only strictly necessary cookies will be activated without prior consent. The Data Subject may modify their preferences at any time through their browser settings or Eden's cookie preferences panel.
13.3 Disabling cookies may affect the functionality of the website.
14. SECURITY MEASURES
Eden implements administrative, technical, and physical security measures designed to protect personal data against unauthorized access, loss, alteration, destruction, or misuse. The measures include, by way of illustration but not limitation:
14.1 Technical measures: (a) encryption of data in transit (TLS/SSL) and at rest (AES-256 or equivalent); (b) multi-factor authentication (MFA) for access to critical systems; (c) role-based access control (RBAC) with the principle of least privilege; (d) continuous monitoring and analysis of access and activity logs; (e) periodic security testing, including penetration testing and vulnerability assessments; (f) timely management of patches and security updates; and (g) segmented network architecture with firewalls and intrusion detection and prevention systems (IDS/IPS).
14.2 Administrative measures: (a) formal information security policies and procedures; (b) periodic security and privacy training for all staff; (c) Data Protection Impact Assessments (DPIAs) for new projects or significant changes in processing; (d) a security incident response plan; and (e) Service Level Agreements (SLAs) with providers that include security and privacy commitments.
14.3 Physical measures: (a) physical access control to the facilities where personal data is processed; and (b) geographic redundancy of backups across multiple locations.
14.4 Certifications. Eden maintains ISO 27001 certification (Information Security Management System) and works continuously to obtain and maintain additional certifications relevant to the health sector.
14.5 Privacy by design in software development. In compliance with the technical guidelines issued by Ecuador's Superintendency for Personal Data Protection (SPDP), Article 14 quáter of Chile's Law 21.719, and Article 25 of the GDPR, Eden will integrate personal data protection into all phases of the software development lifecycle of Eden Suite and its modules. This includes: (a) data selection and minimization from the design phase of each functionality; (b) privacy risk analysis integrated into the development pipeline (DevPrivOps); (c) application security testing (SAST, DAST, SCA) as part of the deployment process; and (d) documentation of design decisions related to privacy and justification of the risk metrics used.
15. SECURITY INCIDENT NOTIFICATION
In the event of a Security Incident that may pose a relevant risk or harm to the rights and freedoms of Data Subjects, Eden undertakes to:
15.1 Notify the competent Data Protection Authority within forty-eight (48) hours from the moment Eden becomes aware of the incident. This period adopts the most demanding standard among Eden's jurisdictions of operation (Peru, D.S. 016-2024-JUS, Article 34).
15.2 Notify the affected Data Subjects without undue delay when the incident may entail a high risk to their rights and freedoms.
15.3 Document all security incidents, including their effects and the corrective measures adopted.
15.4 Where Eden acts as a processor, notify the controller (Client) without delay so that the controller can comply with its notification obligations.
15.5 In Peru, additionally, notify the National Center for Digital Security when the incident occurs in digital environments, in accordance with the Regulation of the Personal Data Protection Law.
16. RETENTION PERIODS
16.1 Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, in accordance with the following criteria: (a) for as long as the legal relationship giving rise to the processing subsists; (b) during the limitation period for legal or contractual actions arising from that relationship; (c) during the period required by applicable regulations (tax, labor, health, among others); and (d) when judicial, administrative, or arbitral proceedings are pending.
16.2 Once the applicable retention periods have elapsed, personal data will be securely deleted or irreversibly anonymized.
16.3 Blocking period. During the period between the fulfillment of the purpose and the definitive deletion, personal data will be blocked and may only be accessed to determine legal or contractual liabilities.
17. ANONYMIZATION AND USE OF DISSOCIATED DATA
17.1 Eden may carry out irreversible anonymization processes of personal data for the following purposes: (a) scientific research and technological development; (b) statistical analysis and the development of metrics; (c) improvement of artificial intelligence algorithms and machine learning models; and (d) market studies and commercial analysis.
17.2 Once data has been subjected to an irreversible anonymization process, it ceases to be personal data and, therefore, its further processing is not subject to the provisions of this Notice or of applicable personal data protection law.
17.3 Eden documents the anonymization methods used and periodically assesses the risk of re-identification.
18. AUTOMATED DECISIONS AND ARTIFICIAL INTELLIGENCE
Eden uses artificial intelligence models in the Eden AI and AI Report modules of Eden Suite. It is essential that the Data Subject understands the following:
18.1 No autonomous diagnosis. Eden AI provides diagnostic support; it does not replace the physician's clinical judgment. Every result generated by Eden AI is a suggestion that must be evaluated, validated, or discarded by a qualified medical professional.
18.2 AI Report requires a physician's signature. AI Report transforms medical dictation into structured drafts. No draft is released as a final report without the review and signature of the responsible physician.
18.3 Eden Creator does not generate diagnoses. Eden Creator assists in drafting medical conclusions but does not produce clinical diagnoses.
18.4 Guaranteed human intervention. In no case will a clinical or medical decision be adopted on an exclusively automated basis. The Data Subject has the right to request human intervention, to express their point of view, and to contest the decision.
18.5 Algorithmic transparency. The Data Subject has the right to obtain meaningful information about the logic applied in the automated processing of their data, as well as about the significance and the envisaged consequences of such processing.
18.6 Compliance with the EU Artificial Intelligence Regulation (AI Act). Eden recognizes that the Eden AI and AI Report modules, by operating on health data through artificial intelligence models, may be classified as high-risk AI systems under Regulation (EU) 2024/1689 (AI Act). Consequently, Eden will adopt the following measures with respect to these modules:
18.6.1 Risk management system: implementation of a continuous system for identifying, analyzing, estimating, and evaluating the risks associated with the use of Eden AI.
18.6.2 Data governance: the datasets used for training, validation, and testing of the AI models will meet criteria of quality, representativeness, and absence of bias, to the extent technically feasible.
18.6.3 Technical documentation: Eden will maintain up-to-date technical documentation that allows competent authorities to assess compliance with the applicable requirements.
18.6.4 Record-keeping and traceability: the AI systems will generate automatic records (logs) that allow the functioning of the system to be traced throughout its lifecycle.
18.6.5 Human oversight: Eden AI is designed to be used under the supervision of a qualified medical professional. The system architecture prevents the release of results without human intervention.
18.6.6 Accuracy, robustness, and cybersecurity: Eden will apply measures to ensure adequate levels of accuracy, robustness, and cybersecurity of the AI models, including periodic testing and post-deployment monitoring.
18.7 These obligations will apply regardless of the Data Subject's jurisdiction, as part of Eden's commitment to the highest global standards. In jurisdictions where no specific AI legislation exists, Eden will adopt these measures as a voluntary best practice.
19. DATA PROTECTION OFFICER (DPO)
19.1 Eden has designated a Data Protection Officer (DPO) as the point of contact for all matters related to the processing of personal data. The DPO is accessible in Spanish, Portuguese, and English through the following means: (a) email: legal@edenmed.com; and (b) postal address: Higia, Inc. — Attn: Data Protection Officer — 300 Delaware Ave., Suite 210 #215, Wilmington, DE 19801, USA.
19.2 The DPO has the following functions: (a) to oversee compliance with this Notice and applicable law; (b) to advise Eden on Data Protection Impact Assessments; (c) to serve as a point of contact for Data Subjects and Data Protection Authorities; and (d) to cooperate with Data Protection Authorities in the exercise of their functions.
19.3 In Ecuador, Eden's DPO must be registered with the SPDP in accordance with Resolution SPDP-SPD-2025-0028-R. In Brazil, they will act as Encarregado in accordance with Article 41 of the LGPD. In Peru, they will act as Personal Data Officer in accordance with D.S. 016-2024-JUS. Eden may designate a single DPO for the corporate group, as permitted by applicable laws, provided they can carry out their functions in each jurisdiction.
20. ACCEPTANCE OF THE PRIVACY NOTICE
Acceptance of this Notice is governed by the following principles:
20.1 Affirmative consent. Eden does not presume the Data Subject's consent from the mere use of the website or services. Where consent is the legal basis for the processing, Eden will request a clear affirmative action from the Data Subject (opt-in).
20.2 Granularity. The Data Subject may grant their consent in a differentiated manner for each purpose of the processing, where the applicable law so requires.
20.3 Revocability. Consent may be withdrawn at any time, as simply as it was granted.
21. UPDATES TO THE PRIVACY NOTICE
21.1 Eden reserves the right to modify this Notice at any time to adapt it to regulatory, jurisprudential, technological, or operational changes. Any substantial modification will be communicated to the Data Subject through: (a) publication on the website legal.edenmed.com, with a clear indication of the date of last update; (b) notification by email to Data Subjects whose address Eden holds, when the modification affects previously granted rights; and (c) notice within the Eden Suite platform, when the modification affects platform Users.
21.2 Where the modification requires new consent from the Data Subject, Eden will request it explicitly before the modification takes effect.
22. DATA PROTECTION AUTHORITIES AND COMPLAINTS
22.1 Without prejudice to the Data Subject's right to contact Eden directly, the Data Subject has the right to file a complaint with the competent Data Protection Authority in their jurisdiction. The main authorities in Eden's jurisdictions of operation are listed below:
22.1.1 Mexico — Competent authority for personal data protection. Main legal framework: LFPDPPP and its Regulations.
22.1.2 Brazil — ANPD (Autoridade Nacional de Proteção de Dados). Main legal framework: LGPD (Law No. 13.709/2018).
22.1.3 Colombia — SIC (Superintendencia de Industria y Comercio). Main legal framework: Law 1581 of 2012 and Decree 1377 of 2013.
22.1.4 Peru — ANPDP (Autoridad Nacional de Protección de Datos Personales). Main legal framework: Law 29733 and its Regulations.
22.1.5 Ecuador — SPDP (Superintendencia de Protección de Datos Personales). Main legal framework: LOPDP (Organic Law on Personal Data Protection).
22.1.6 Chile — Personal Data Protection Agency (under implementation). Main legal framework: Law 19.628 and Law 21.719.
22.1.7 European Union — Supervisory authority of the relevant member state. Main legal framework: GDPR (Regulation (EU) 2016/679).
22.1.8 United States — FTC (Federal Trade Commission) and state authorities. Main legal framework: applicable federal and state legislation (HIPAA, CCPA/CPRA, among others).
22.2 Eden reaffirms its willingness to resolve any dispute promptly and amicably through its DPO, without prejudice to the Data Subject's right to approach the competent authorities.
23. APPLICABLE LAW AND JURISDICTION
23.1 This Notice is interpreted and applied in accordance with the personal data protection legislation in force in each jurisdiction where Eden operates. In the event of a conflict between provisions of different jurisdictions, the interpretation most favorable to the Data Subject will prevail, in accordance with the principle of Automatic Maximum Protection established in Clause 3 of this Notice.
23.2 For any dispute arising from the processing of personal data, the courts of the jurisdiction of the Data Subject's domicile will have jurisdiction, unless the applicable law establishes a different rule.
24. CONTACT
24.1 For any question, request, or complaint: (a) email: legal@edenmed.com; (b) postal address: Higia, Inc. — Attn: Data Protection Officer — 300 Delaware Ave., Suite 210 #215, Wilmington, DE 19801, USA; (c) languages of service: Spanish, Portuguese, and English; and (d) EU representative: contact details available at legal.edenmed.com.