Legal

Privacy Policy

Last updated: August 12, 2026

VynMed Inc. ("the Company") is committed to protecting the privacy of its users and clients. This Privacy Policy explains how the Company collects, uses, discloses, and safeguards information when using VynScan, our rapid test strip recording platform, and associated services.

1. Information We Collect

Test Images and Data

VynScan captures digital images of rapid infection test strips (such as COVID, flu, RSV, and strep) to preserve a tamper-evident record. These images may contain visual indicators that could be associated with individuals being tested. Image metadata, including timestamps and device identifiers, is collected when the record is captured.

Device Data

When VynScan devices are used, the Company collects:

  • Device identifier and serial number
  • Software version and firmware information
  • Device location and facility association
  • Usage statistics and performance metrics

User Account Information

For users who create accounts to access VynScan records, the Company collects:

  • Name and email address
  • Job title and role
  • Facility or organization affiliation
  • Authentication credentials

Facility Data

For nursing homes and other facilities using VynScan, the Company may collect information about:

  • Facility name and location
  • Number of tests conducted
  • Facility administrator and authorized user information

Automatically Collected Information

The Company may automatically collect:

  • IP addresses and device information
  • Usage patterns and interaction data
  • Error logs and system diagnostics

2. How We Use Information

VynMed uses collected information for the following purposes:

  • Strip Recording: To capture the strip image and store a tamper-evident, timestamped record of each test.
  • Quality Assurance: To confirm the device captured a clean, complete record and to maintain system reliability.
  • Product Improvement: To improve VynScan's software, user interface, and overall performance through analysis of usage patterns.
  • Security: To detect and prevent fraud, unauthorized access, and security threats.
  • Compliance: To comply with applicable healthcare regulations, including HIPAA and facility-specific policies.
  • Customer Support: To provide technical assistance and resolve issues.
  • Legal Obligations: To respond to lawful requests from regulators and law enforcement.

3. HIPAA Compliance Pathway

HIPAA Business Associate Agreement Framework: VynMed is designed with a Business Associate framework under the Health Insurance Portability and Accountability Act (HIPAA). Facilities using VynScan should execute a Business Associate Agreement (BAA) with the Company to establish the terms for handling Protected Health Information (PHI).

Protected Health Information (PHI) Handling

When VynScan processes information that constitutes PHI under HIPAA:

  • PHI is processed only for the purposes specified in the BAA.
  • The Company implements administrative, physical, and technical safeguards to protect PHI.
  • PHI is not used for any purpose other than providing VynScan services unless explicitly authorized in writing.
  • The Company does not sell PHI.

Individual Rights

Covered entities (healthcare facilities) using VynScan remain responsible for honoring patient requests to access, amend, or receive an accounting of disclosures of their PHI. The Company will cooperate with reasonable requests to support these rights.

4. Data Storage & Security

Encryption

The Company employs industry-standard encryption protocols:

  • In Transit: All data transmitted between VynScan devices, applications, and servers is encrypted using TLS 1.2 or higher.
  • At Rest: Data stored in VynMed's systems is encrypted using AES-256 or equivalent encryption standards.

Access Controls

The Company implements:

  • Role-based access controls (RBAC) to limit data access to authorized personnel only.
  • TOTP multi-factor authentication is supported and available for user and administrative accounts; enforcement is being rolled out per group and is not yet switched on.
  • Regular access reviews to ensure data is accessed only on a need-to-know basis.
  • Audit logs to track access to sensitive data.

Infrastructure Security

VynMed's data storage and processing infrastructure is hosted on AWS (Amazon Web Services), in the us-east-2 (Ohio) region by default. AWS is HIPAA-eligible under a Business Associate Agreement (BAA) and SOC 2 audited. Data center physical access, network controls, hardware lifecycle, and threat detection are AWS's responsibility under the shared-responsibility model. VynMed's responsibilities include:

  • Encryption at rest (AWS KMS) for evidence images and audit logs.
  • Encryption in transit (TLS 1.2+) for every connection between the device, the portal, and the API.
  • Regular security updates and patch management on application code.
  • CloudTrail logging of control-plane activity, with CloudWatch alarms on security-relevant events.
  • Periodic security review of the application layer (third-party penetration testing planned).

5. Data Retention

The Company retains data for as long as necessary to provide VynScan services and comply with applicable legal and regulatory requirements. HIPAA requires covered entities to retain administrative records (including audit logs and access records) for a minimum of six years from the date of creation or the date when last in effect, whichever is later. VynMed retains these records for seven (7) years, exceeding that minimum, and for any longer retention period required by state law, facility policy, or contractual obligation. Specifically:

  • Test images, and the session records that accompany them, are retained for seven (7) years from the point each one is written to storage. They are written to write-once, tamper-evident storage and cannot be deleted or altered before that period ends. Ending the service agreement between a facility and VynMed stops all further collection and revokes access; it does not delete images already captured.
  • User account information is retained while the account is active. Upon account deletion, personal information is securely deleted within 30 days, except where the law requires otherwise or where the record is already held in the write-once storage described below.
  • Audit logs and security data are retained for seven (7) years from the date of creation, exceeding the HIPAA §164.316(b)(2) six-year minimum. They are held in the same write-once storage as test images and are subject to the same limit: they cannot be deleted before that period ends.
  • Facilities may request deletion of the records that are not held in write-once storage, in accordance with applicable law and the service agreement. What such a request can and cannot reach is set out below.

Write-once storage, and what it means for a deletion request

Test images and audit entries are stored using Amazon S3 Object Lock in COMPLIANCE mode, with a seven-year retention period that starts when the record is written. In that mode no one can delete a record or shorten its retention before it expires. That includes VynMed staff, and it includes the owner of the underlying AWS account.

This is a deliberate design decision rather than a limitation the Company works around. A record of a test that VynMed could quietly delete or alter would not serve as evidence that the test happened, and the same immutability is what allows the audit trail to be tamper-evident.

A request to delete, whether it comes from a facility at the end of a contract or from an individual, is therefore answered in two parts:

  • What the Company can do. Close the account, revoke access for every user at the facility, stop all further collection of images and session records, and, on written request, purge the facility's directory records and index entries from the operational database.
  • What the Company cannot do. Destroy test images or audit entries already written to write-once storage before their seven-year retention expires. Once it expires, those records are deleted.

VynMed's Business Associate Agreement states this position at section 7.3, relying on the exception at 45 CFR 164.504(e)(2)(ii)(J) for protected health information whose return or destruction is not feasible. The protections of that agreement continue to apply to the retained records for the remainder of the retention period.

6. Third-Party Sharing

Data Sale Policy

VynMed does not sell, rent, or share personal information or PHI with third parties for marketing or commercial purposes.

Limited Sharing for Service Operation

The Company may share information with trusted third parties only as necessary to provide VynScan services:

  • Service Providers: Cloud infrastructure providers, data storage services, and technical support vendors who have signed data processing agreements ensuring equivalent data protection.
  • Facility Administrators: Authorized users at the healthcare facility may access test results and facility data in accordance with their permissions and facility policies.
  • Legal Compliance: VynMed may disclose information when required by law, court order, or government request, provided the Company notifies the affected party unless legally prohibited.

Data Processing Agreements

All third-party service providers who handle data sign Data Processing Agreements (DPAs) that:

  • Limit data use to the specific purposes outlined in the agreement.
  • Require equivalent security measures.
  • Restrict further data sharing without consent.
  • Include audit rights for VynMed and its clients.

7. Your Rights

Access

Subject to applicable laws and regulations, individuals or authorized representatives may request access to their personal information or PHI that VynMed processes. Requests should be directed to the contact information provided in Section 10.

Correction

If inaccuracies are identified in personal information, individuals may request correction. The Company will work to verify and correct such information promptly.

Deletion

Individuals may request deletion of their personal information, subject to legal retention requirements and ongoing service obligations. The Company will honor deletion requests where feasible and will securely dispose of data no longer needed. Test images and audit entries held in write-once storage cannot be deleted before their seven-year retention expires; Section 5 sets out what a deletion request reaches and what it does not.

Data Portability

Where applicable under data protection regulations, individuals may request that their data be provided in a structured, commonly used, and machine-readable format.

Exercising Your Rights

To exercise any of these rights, please contact VynMed using the contact information in Section 10. The Company will respond to requests within the timeframes required by applicable law, typically within 30 days.

8. Children's Privacy

VynScan is a workplace healthcare device for use by trained staff in skilled-nursing and similar regulated facilities; it is not directed to children. The Company does not knowingly collect personal information from minors except as part of the resident or patient record at the operating facility, where data collection is governed by the facility's own HIPAA-compliant policies and parental/guardian-consent processes (not by VynMed).

Specifically:

  • Under 13: the Company does not knowingly collect personal information directly from any individual under 13. If the Company becomes aware that information from a child under 13 has been collected outside of a facility's authorized operational records, it will take immediate steps to delete such information.
  • Ages 13 to 17: where a facility uses VynScan to test a minor resident or patient, the legal responsibility for parental/guardian notice and consent rests with the operating facility under HIPAA, state law, and the facility's own privacy practices. VynMed acts as a Business Associate to the facility under HIPAA §164.502(e); we do not contact minors or their parents directly.
  • Account creation: the VynMed portal and mobile app are not available to users under 18. Facility-admin accounts are restricted to staff in their professional capacity.

Parents or guardians who believe their child's information has been collected by VynMed outside of an authorized facility record should contact us immediately at contact@vynmed.com.

9. Changes to This Policy

VynMed may update this Privacy Policy from time to time to reflect changes in practices, technology, legal requirements, or other factors. The Company will notify users of material changes by updating the "Last updated" date at the top of this policy and, where applicable, by providing notice through VynScan or other communication channels.

Continued use of VynScan following changes to this Privacy Policy constitutes acceptance of the updated policy. Users are encouraged to review this policy periodically to stay informed about how VynMed protects their information.

10. Contact Information

For questions about this Privacy Policy, data requests, or to exercise your privacy rights, please contact:

VynMed Inc.

Henderson, Nevada

Phone: (702) 900-8503

Email: contact@vynmed.com

For HIPAA-related inquiries or Business Associate Agreement questions, please include "HIPAA" in the subject line of your communication.

The Company will respond to inquiries within 10 business days and will work to address any concerns regarding privacy and data protection.

By using VynScan, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree with any part of this policy, please discontinue use of VynScan.