Last updated: September 2026
1. Data Controller
AIXHORN S.A.S. ("AIXHORN"), a company organized under the laws of Colombia with its principal place of business in Medellín, Colombia, is the data controller ("Responsable del Tratamiento") for personal data processed through the rödea application, in accordance with Colombian Law 1581 of 2012 and Decree 1377 of 2013.
2. Sensitive data notice and prior authorization
Health data is legally classified as sensitive personal data ("dato sensible") under Colombian law. By accepting a care-group administrator invitation, or by recording, uploading, or connecting a device to record a Care Recipient's health information, you give AIXHORN your prior, express, and informed authorization to process that sensitive data for the purposes described in this Policy. You are not obliged to authorize the processing of sensitive data; however, if you do not, AIXHORN will not be able to provide the Care Group features that depend on it (such as centralizing medications, vitals, or lab results).
If the Care Recipient is not the person providing this authorization (for example, a family member registers information on their behalf), the person doing so confirms they have the authority to do so — as the Care Recipient's legal guardian, or as otherwise authorized by the Care Recipient or applicable law.
3. What we collect in the Application
- Account data: name, email, phone, country, language, and timezone.
- Care Group data: Care Group membership, roles, and invitations.
- Health and care data: basic health information (prior diagnoses, allergies, notes), medications and schedules, appointments, tasks, care plans, and lab results (documents, images, or form entries).
- Device and vitals data: readings synced from Connected Devices (e.g., heart rate, SpO2, heart-rate variability, body temperature, motion/posture) and manually entered readings (e.g., glucose, blood pressure).
- Communications data: messages exchanged with the WhatsApp/Telegram assistant, and the phone number or account identifier used to send them.
- Usage and diagnostic data: logs generated when you interact with the Application, used to keep it reliable and secure.
4. Purpose
We use this data to: operate the Application; let a Care Group centralize and view care information; generate reminders, notifications, and reports for the Care Group; respond to Members through the AI assistant; and secure the Application against misuse. As described in the Application Terms of Service, we do not use this data to generate diagnoses, clinical alerts, risk scores, or treatment recommendations. Any pattern or summary shown in the Application is limited to general informational and wellness purposes, intended to help a Care Group understand what happens between qualified medical visits.
5. De-identified and Aggregate Data
AIXHORN may irreversibly de-identify records collected through the Application — removing or obscuring the elements that would reasonably allow a Care Recipient or Member to be identified — and use or share this de-identified information for purposes other than the Application's primary care-coordination purpose, such as product research, analytics, service improvement, training and improving AI models (including the assistant described in Section 5 of the Application Terms of Service), and aggregated statistics shared with research or analytics partners. Under Colombian Law 1581 of 2012, properly de-identified data that cannot reasonably be traced back to a person is no longer considered personal data, so this processing is not subject to the rights and restrictions described elsewhere in this Policy.
AIXHORN does not attempt to re-identify de-identified records, does not use this data for health-profile advertising, and does not sell it. If you would prefer a Care Group's data not be used this way, you (or the Care Group's Administrator) can opt out at any time by writing to [email protected], without affecting the Care Group features you already rely on.
6. Data Sharing
Data recorded in a Care Group is visible to the Members and the Administrator of that Care Group, according to the roles and permissions the Administrator configures. We do not sell personal data. We share it only with:
- infrastructure and hosting providers that store Application data;
- the messaging platforms you choose to use — WhatsApp Business Platform (operated by Meta) and Telegram — to deliver and receive assistant messages;
- third-party AI providers that process assistant conversations on AIXHORN's behalf, under contractual confidentiality and data-processing obligations;
- Connected Device manufacturers or their platforms, to the extent necessary to read the data you authorize the Application to access;
- research or analytics partners, limited to the de-identified or aggregated data described in Section 5;
- authorities, where required by applicable law.
7. Your Rights
As a data subject under Colombian Law 1581 of 2012, you (or, where applicable, the Care Recipient's legal guardian) have the right to: know, update, and rectify personal data; request proof of the authorization given; be informed about the use given to the data; revoke the authorization and/or request deletion when there is no legal duty to retain it; access the data free of charge; and file complaints regarding data handling before the Superintendencia de Industria y Comercio (SIC).
To exercise these rights, contact us at [email protected]. Queries are answered within 10 business days (extendable by 5) and claims within 15 business days, as required by law. Revoking authorization for sensitive data may mean the Application can no longer provide the Care Group features that depend on it.
8. Security Measures
Given the sensitivity of the data involved, we apply role-based access control so that only Members you invite can see a Care Group's data, encryption in transit and at rest, and an internal audit trail of changes to health and care records. We also rely on the security and observability tooling of our infrastructure and platform providers — such as monitoring, intrusion detection, and automated backups — to help protect and oversee the systems that store this data. No system is completely secure, and we encourage Administrators to use a strong, unique password and to remove Members promptly when their role in a Care Group ends.
9. Data Retention
We retain Care Group data for as long as the Care Group's plan remains active. When an Administrator terminates a Care Group or account, we delete the associated health and care data within a reasonable period, except where we are required to retain it for legal, accounting, or dispute-resolution purposes, or where it has been de-identified as described in Section 5.
10. Minors and Care Recipients Who Cannot Consent
Where a Care Recipient is a minor or otherwise unable to provide authorization themselves, only their parent, legal guardian, or another person legally authorized to act on their behalf may register their health information in the Application.
11. International Data Transfers
Some processing described above (hosting, messaging platforms, AI providers) may occur outside Colombia. When this happens, we take steps to ensure the data continues to receive an appropriate level of protection.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where required, by requesting renewed authorization inside the Application.
13. Contact
Questions about this Policy, or requests to exercise your rights, can be sent to [email protected].