ReadyAED privacy policy
What personal data we handle, why we handle it and the choices you have.
This page explains how ReadyAED handles personal data. Personal data is information about a person. This page is for anyone who visits readyaed.co or uses the ReadyAED platform.
The plain-language summary comes first. The full text follows it. The full text marks every clause that needs legal approval.
ReadyAED is an AED (automated external defibrillator) readiness and compliance platform. It is software only. It sells no hardware and no consumables.
Plain-language summary
This summary is not the legal text. If the summary and the legal text disagree, the legal text wins.
We handle personal data to run the platform for your organisation. The data includes account and user records, site and location records, AED device records, inspection records, documents and the audit trail.
Your team enters most of that data. The platform records the rest, such as status changes and history events. We use the data to run the software, keep the records and support your team. legal-approved purposes of processing and lawful bases
We share data with subprocessors. A subprocessor is a vendor that processes data for us. The list is not published yet. subprocessor list legal-approved recipients and disclosure terms
You can ask about your personal data. Ask through the Contact page, which names the privacy and legal route. ReadyAED does not route a privacy request through sales. The privacy contact details are not published yet. legal-approved privacy rights and how to exercise them
Full legal text
The clauses below are the operative text. Each clause needs legal approval before it is binding. this passage needs legal sign-off
Who we are
ReadyAED provides the software described on this site. The company that controls the personal data (the controller) is not named in this draft. legal-approved controller identity and registered address
What we collect
Your team creates most of the data that the platform holds. The platform also records events as work happens.
- Account and user records, with work email, name and initials.
- Site and location records, with building, floor and room paths.
- AED device records, with brand, model, serial number, asset ID, pads expiry, battery percentage and status.
- Inspection records, with the date, the inspector, five checklist answers, the result and optional notes and photos.
- Documents, such as manuals, certificates and service records.
- The audit trail, with user and system events, device history and inspection history.
A note or a photo can hold health details when your team puts them there. A BAA (Business Associate Agreement) is available. The BAA applies to that case. BAA request process and turnaround — legal confirmation needed
The exact categories for privacy law need legal approval. legal-approved categories of personal data
Why we use it
We use personal data to run the platform for your organisation. The lawful bases for that use need legal approval. legal-approved purposes of processing and lawful bases
Who we share it with
We use subprocessors. A subprocessor is a vendor that processes data for us. The list is not published yet. subprocessor list Read the Subprocessors page.
Other recipients and disclosure terms need legal approval. legal-approved recipients and disclosure terms
Where the data goes
The app offers a data-region selector with five regions: US, UK, EU, India and APAC. The selector is a product setting. confirmation of data residency options legal-approved international transfer safeguards
How long we keep it
How long we keep each record is not published yet. legal-approved retention periods
Your rights
Privacy laws in some markets give people rights over their personal data. The rights can include access, correction, deletion, restriction, objection and portability. The exact rights depend on where you live. legal-approved privacy rights and how to exercise them legal-approved privacy contact and response times
Children
The platform is a workplace tool. It is not made for children. legal-approved children's data position
Security
The platform keeps an audit trail of user and system events, device history and inspection history. A BAA (Business Associate Agreement) is available. The BAA applies when protected health information is involved. Read the Security & Trust Center and the HIPAA & data handling page.
Security controls are not confirmed for publication yet. security controls evidence (encryption, hosting, backups, penetration testing) — product and legal confirmation required
Approval status
The wording above is not final. It needs legal approval before it is binding. legal-approved disclaimer text this passage needs legal sign-off
Effective date
The effective date is not published yet. legal-approved effective date
Change process
The change process for this policy is not published yet. legal-approved change notice process this passage needs legal sign-off
Contact
Privacy questions and requests go through the Contact page. The page names the privacy and legal route, and ReadyAED does not route a privacy request through sales. The privacy contact address and the response times are not published yet. legal-approved privacy contact and response times
If your organisation needs a Data Processing Agreement, read the Data processing agreement page. You can also change your cookie choices on the Cookie settings page.