CEVEON Privacy Policy
Personal Data Controller: Ceveon Inc., Miami, Florida, United States
Data Protection Contact: info@ceveon.com | Support: support@ceveon.com | Website: www.ceveon.com
Ceveon Inc. does not sell your personal information.
Compliance scope: Apple App Store (Section 5.1 Guidelines), Google Play Data Safety, GDPR (EU/UK), CCPA/CPRA (California), HIPAA (Business Associate where applicable), COPPA, and applicable U.S. state privacy laws.
1. Introduction
Ceveon, Inc. ("Ceveon," "we," "us," or "our") is a technology company headquartered in Miami, Florida, operating a smart occupancy detection and operational automation platform designed for assisted living facility operators and their authorized personnel. The Ceveon platform combines mmWave radar sensor hardware with machine learning to support occupancy monitoring, NOI (Net Operating Income) improvement analytics, and resident safety.
This Privacy Policy ("Policy") describes how we collect, use, store, disclose, and protect personal data obtained through our:
Mobile application (iOS and Android)
Web-based dashboard and operator portal
mmWave radar sensor hardware and associated firmware
SMS communications and customer support channels
Website at www.ceveon.com
(collectively, the "Services" or "Products")
This Policy applies to facility operators, administrators, and authorized staff who use the Services; residents of assisted living facilities whose data is processed through the Services; and authorized family members or legal representatives of residents.
By downloading, installing, or using the Ceveon App, or by interacting with our Services in any way, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use and contact us at info@ceveon.com.
For users under the age of 13, please refer to Section 9 (Children's Privacy) and our standalone Children's Privacy Statement at www.ceveon.com/child-protection.
2. Definitions
Personal Data means any information that can identify an individual directly or indirectly, including name, email, device identifier, location data, health information, or behavioral data.
Sensitive Personal Data includes biometric information, health and vital sign data, precise location, communication records, and financial information. Ceveon applies heightened protection to all Sensitive Personal Data.
Smart Devices refers to Ceveon mmWave radar sensor packages and other connected hardware deployed within assisted living facilities.
Facility Operator means the assisted living facility or its authorized management entity that contracts with Ceveon for use of the Services.
Protected Health Information (PHI) has the meaning given under HIPAA. Where Ceveon processes PHI on behalf of a covered entity, Ceveon acts as a Business Associate.
3. Personal Data We Collect
3.1 Account and Registration Data
Full name, email address, phone number, and job title
Account credentials (passwords stored in hashed/encrypted form only)
Country, language preference, and time zone
Profile picture or avatar (if voluntarily provided)
Home or business address (for operator account setup or billing)
3.2 Payment and Billing Data
Payment method data processed via secure third-party payment providers (credit/debit card, bank transfer, PayPal, Apple Pay, or other providers)
Billing address and VAT/tax identification number where required
Transaction history, subscription status, and refund records
Ceveon does not directly store full payment card numbers. Payment data is handled exclusively by PCI-DSS compliant third-party processors.
3.3 Health and Biometric Data
The Ceveon platform uses mmWave radar sensor technology to passively collect:
Occupancy detection and movement patterns within facility zones
Passive vital sign indicators (e.g., respiratory rate cadence, movement-derived activity levels) where enabled
Inactivity and fall detection event data
This data is treated as Sensitive Personal Data and is associated with resident profiles only as directed and authorized by the Facility Operator. Where this constitutes Protected Health Information (PHI), Ceveon operates as a Business Associate under HIPAA.
A signed Business Associate Agreement (BAA) is required before Ceveon processes PHI on behalf of any covered entity. Contact info@ceveon.com to initiate a BAA.
3.4 Location Data
Facility address and geographic location provided during account setup
In-facility occupancy zone data derived from sensor readings (room/area level — not GPS tracking of individuals)
Device-level location may be collected during use to associate the device with the correct facility network; precise background location is not collected
Geo-fence or automation-trigger location where explicitly enabled by the Facility Operator
3.5 Smart Device Data
Device name, device ID, model, serial number, firmware version, and online/offline status
Device pairing and network configuration data (Wi-Fi SSID, MAC address, Zigbee/Matter/Wi-Fi pairing identifiers)
Automation history, scene configurations, and scheduled actions
Device event logs, alert triggers, and error/diagnostic reports
Information stored on a device only when provided for service or repair
3.6 Device and Usage Data (Automatically Collected)
Mobile device model, operating system type and version, app version number
IP address, network type, and wireless connection information
Push notification identifiers and device tokens
App session data: features accessed, session duration, interaction patterns, navigation flows
Crash reports, exception logs, and performance diagnostics
Log data: timestamps, access dates, language settings
3.7 Communications and Support Data
Emails, in-app messages, and support ticket content submitted to Ceveon
SMS messages exchanged as part of customer support (see Section 14)
Survey responses, contest entries, and campaign participation data
Feedback and feature request submissions
3.8 Marketing and Communications Preferences
Email address and communication channel preferences (email, SMS, push notifications)
Opt-in/opt-out status for marketing and promotional communications
Contest, survey, and promotional campaign participation data
3.9 Anonymized and Aggregated Data
We may derive anonymized or aggregated statistical data from personal data for product improvement, industry benchmarking, and operational analytics (e.g., aggregate occupancy trends, NOI metrics). Such data cannot reasonably re-identify individuals and is not treated as personal data.
4. Purposes and Legal Basis for Processing
4.1 Service Delivery (Contractual Necessity)
Authenticate users and provide access to the Ceveon platform
Enable device pairing, remote control, automation, and scheduling
Operate occupancy detection, alert systems, and NOI analytics dashboards
Process payments, subscriptions, and in-app purchases
Provide warranty, repair, and maintenance services
Send service-critical notifications (device alerts, security events, status updates)
4.2 Resident Safety and Care (Contractual Necessity / Vital Interests)
Enable fall detection, inactivity alerts, and emergency response notifications
Support care staff in monitoring resident wellbeing as directed by the Facility Operator
Generate compliance and care quality reports for operators
4.3 Platform Improvement (Legitimate Interests / Consent)
Analyze usage patterns to improve product features, performance, and user experience
Train and improve machine learning models using de-identified or aggregated data only
Conduct crash diagnostics and resolve technical issues
To opt out of non-essential analytics: App &rt; Settings &rt; Privacy Settings &rt; Data Analysis.
4.4 Marketing and Personalization (Consent)
Send direct marketing communications with your explicit prior consent
Personalize product recommendations and interface experiences
Administer contests, surveys, and promotional campaigns
To withdraw consent: App &rt; Settings &rt; Privacy Settings &rt; Personalization, or click Unsubscribe in any marketing email.
4.5 Legal Compliance (Legal Obligation)
Comply with applicable federal and state laws, regulations, and court orders
Enforce Terms of Service and contractual agreements
Respond to lawful requests from government authorities
Conduct fraud detection, security monitoring, and risk management
4.6 GDPR Legal Bases (EEA/UK Users)
Contractual necessity — to deliver contracted services
Legitimate interests — product improvement, security, fraud prevention (where not overridden by your rights)
Legal obligation — compliance with applicable law
Consent — may be withdrawn at any time without affecting prior processing
Vital interests — in emergency situations involving resident safety
5. Device Permissions and Additional Functions
Certain features require specific device permissions. You may enable or disable these at any time through your device settings. Disabling a permission limits related functionality but does not affect prior data collection.
5.1 Location
Used to associate your device with the correct facility network and support geo-fence automations.
iOS: Settings &rt; Privacy & Security &rt; Location Services &rt; Ceveon
Android: Settings &rt; Apps &rt; Ceveon &rt; Permissions &rt; Location
5.2 Camera
Used for QR code scanning to pair Smart Devices. Camera access is only activated when you initiate a scan.
iOS: Settings &rt; Privacy & Security &rt; Camera &rt; Ceveon
Android: Settings &rt; Apps &rt; Ceveon &rt; Permissions &rt; Camera
5.3 Notifications
Used to deliver real-time device alerts, occupancy events, and care notifications.
iOS: Settings &rt; Notifications &rt; Ceveon
Android / In-App: Settings &rt; Message Center &rt; Notification Settings
5.4 Bluetooth
Used to discover and configure Smart Devices in proximity; activated only during pairing and management scenarios.
iOS: Settings &rt; Privacy & Security &rt; Bluetooth &rt; Ceveon
Android: Settings &rt; Apps &rt; Ceveon &rt; Permissions &rt; Nearby Devices
5.5 Storage (Android)
Used to read/write files including crash logs and media uploads. Settings &rt; Apps &rt; Ceveon &rt; Permissions &rt; Files and Media.
5.6 Microphone (if applicable)
If voice-activated features are enabled, the microphone is used only when you actively initiate a voice command. Microphone access is never continuous or passive.
5.7 HealthKit (iOS)
If connected to Apple Health, Ceveon may exchange activity or health sensor data with the iOS Health app. This is opt-in only and may be disabled via iOS Settings &rt; Privacy & Security &rt; Health &rt; Ceveon.
5.8 HomeKit (iOS)
If enabled, Ceveon interacts with your iOS Home app to discover and configure compatible Smart Devices. Disable via iOS Settings &rt; Privacy & Security &rt; HomeKit &rt; Ceveon.
6. How We Share Your Personal Data
Ceveon does not sell your personal data. We do not share personal data with advertisers or behavioral marketing platforms. We may share data only in the following limited circumstances:
6.1 Cloud Infrastructure and Storage Providers
Third-party cloud hosting and database providers store and process data on our behalf as data processors under contract, prohibited from independent use of your data. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
6.2 Within the Facility Organization
Data associated with a facility account is accessible to authorized administrators and staff of that facility as configured by the Facility Operator. Ceveon does not control internal data access policies within a facility.
6.3 Service Providers
Cloud hosting and database infrastructure providers
Payment processing providers (PCI-DSS compliant)
Customer support and helpdesk platforms
Email, SMS, and push notification delivery services
Analytics and crash reporting tools (receiving de-identified/aggregated data only)
Legal, financial, and compliance advisors
All service providers are bound by data processing agreements requiring confidentiality, data minimization, and appropriate security.
6.4 Smart Device and Integration Partners
Where your use of the Services involves third-party smart home platform integration, limited device identification data may be shared with your explicit consent to enable interoperability.
6.5 Marketing Partners
Contact information may be shared with marketing service providers only for delivery of communications you have explicitly opted into, subject to your right to withdraw at any time.
6.6 Legal and Regulatory Disclosure
We may disclose personal data if required by applicable law, subpoena, or court order, or to protect the rights, property, or safety of Ceveon, users, residents, or the public. We will notify you where legally permitted.
6.7 Business Transfers
In a merger, acquisition, or asset transfer, personal data may transfer as part of that transaction. We will notify affected users by in-app notification or email, and provide choices where required by law.
6.8 Affiliates
We may share data with Ceveon affiliated entities for regular business operations, subject to the same data protection obligations described in this Policy.
7. International Data Transfers
Ceveon is headquartered in Miami, Florida, United States. Your personal data may be transferred to and processed in the U.S. or other countries where our service providers operate.
For EEA/UK users, international transfers are conducted using:
EU Standard Contractual Clauses (SCCs) as approved under GDPR Art. 46
UK International Data Transfer Agreements (IDTAs) where applicable
Adequacy decisions where recognized by the relevant authority
Ceveon will comply with applicable data localization requirements where mandated. Contact info@ceveon.com for further information about transfer safeguards.
8. Data Retention
Account and service data: retained for the duration of the active contract plus the applicable statutory limitation period for legal claims
Accounting and payment data: retained as required by applicable tax and accounting law
Sensor and occupancy event data: retained for [INSERT PERIOD] months, then aggregated or deleted
Health/biometric data: per HIPAA minimum necessary standards and as agreed in the applicable BAA
Usage analytics and crash logs: up to 24 months in identifiable form; longer in anonymized/aggregated form
Marketing and communications data: until consent is withdrawn or for [INSERT PERIOD] years after last interaction
Support communications: [INSERT PERIOD] years after resolution
Following the expiry of retention periods, data will be permanently deleted and cannot be restored. Data will not be deleted if there is a pending legal, administrative, or regulatory proceeding.
You may request early deletion of your personal account data at any time. Facility Operators may request deletion of facility-level data by contacting info@ceveon.com.
9. Children's Privacy
9.1 General
The Ceveon App and Services are not directed to individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children without prior verifiable parental or guardian consent.
Note: Residents of assisted living facilities who are adults are covered under the general terms of this Policy. Ceveon does not knowingly process data of minors in its assisted living context.
9.2 Where Child Data May Be Collected
If a product feature requires age verification and determines the user is a minor, we will:
Notify the parent or guardian and obtain verifiable consent before collecting any personal data
Limit data collection to the minimum necessary for the specific feature
Apply heightened security and access restrictions to any data collected from or about minors
9.3 Parental and Guardian Rights
Parents or guardians may at any time request access to, correction of, or deletion of a child's personal data, or withdraw consent for further processing. Contact us at info@ceveon.com. Identity and relationship verification will be required.
9.4 Reporting Unauthorized Collection
If you believe personal data of a child under 13 has been collected without proper parental consent, contact us immediately at info@ceveon.com. We will investigate and delete confirmed unauthorized data promptly.
Full Children's Privacy Statement: www.ceveon.com/child-protection.
10. Data Security
Encryption in transit: TLS 1.2 or higher
Encryption at rest: AES-256
Role-based access controls limiting data access to authorized personnel only
Multi-factor authentication for platform and administrative access
Proprietary algorithms for data isolation, access authentication, and dynamic key-based device-to-cloud encryption
Regular penetration testing and security assessments
Incident response procedures with breach notification compliant with GDPR (72-hour), CCPA, and applicable U.S. state breach notification laws
No method of Internet data transmission is 100% secure. If you believe your account or interaction with Ceveon has been compromised, contact info@ceveon.com immediately.
11. Your Rights and Choices
11.1 Rights Available to All Users
Access: request a copy of personal data we hold (App: Settings &rt; Privacy Settings &rt; Personal Data Export, or email info@ceveon.com)
Correction: request correction of inaccurate or incomplete data (App: Me &rt; Personal Information, or email info@ceveon.com)
Deletion: request deletion of personal data (App: Settings &rt; Account and Security &rt; Delete Account, or email info@ceveon.com)
Restriction: request temporary or permanent restriction on processing
Withdraw consent: withdraw consent for marketing, personalization, or analytics without affecting lawfulness of prior processing
Permission-level consent may also be managed via your device settings (location, camera, Bluetooth, notifications, microphone) or via App: Settings &rt; Privacy Settings.
11.2 California Residents (CCPA/CPRA)
Right to know: categories and specific pieces of personal information collected, used, disclosed, or shared
Right to delete: request deletion subject to legal exceptions
Right to correct: request correction of inaccurate personal information
Right to opt-out of sale or sharing: Ceveon does not sell personal information
Right to limit use of sensitive personal information
Right to non-discrimination for exercising CCPA rights
To submit a CCPA request: email info@ceveon.com or call [INSERT TOLL-FREE NUMBER]. Response within 45 days (one 45-day extension permitted with notice).
11.3 EEA and UK Residents (GDPR/UK GDPR)
Data portability: receive data in a structured, machine-readable format; may request direct transfer to another controller where technically feasible
Object to processing based on legitimate interests: we will cease processing unless we can demonstrate compelling grounds overriding your interests
Object to direct marketing: absolute right to object at any time
Lodge a complaint with your local data protection supervisory authority
Ceveon does not use automated decision-making or profiling that produces legal or similarly significant effects on users.
11.4 iOS-Specific Controls
Limit tracking: iOS Settings &rt; Privacy & Security &rt; Tracking
Per-app permissions: iOS Settings &rt; Ceveon
App Tracking Transparency (ATT): if the App requests cross-app tracking, an explicit consent prompt will appear; change any time in iOS Settings &rt; Privacy & Security &rt; Tracking
HealthKit / HomeKit: iOS Settings &rt; Privacy & Security &rt; Health / HomeKit
11.5 Android-Specific Controls
Permissions: Android Settings &rt; Apps &rt; Ceveon &rt; Permissions
Location, camera, microphone, Bluetooth, and storage may each be individually managed
Ad personalization opt-out: Google Settings &rt; Ads
11.6 Response Timeframes
We respond to all verifiable rights requests within 30 days of receipt. Complex cases may be extended by up to an additional 30 days with written notice. Identity verification is required before processing requests.
12. Apple App Store — Additional Disclosures
The following disclosures support the accuracy of Ceveon's Privacy Nutrition Label in App Store Connect, in accordance with Apple App Store Review Guidelines Section 5.1.
Data Linked to Your Identity:
Contact Info: name, email address, phone number
Financial Info: payment method data (via third-party PCI-DSS compliant processors)
Health & Fitness: passive vital sign indicators and movement/occupancy data
Location: facility-level and in-app zone location data
Identifiers: device ID, user ID, push notification token
Usage Data: app interactions, session data, crash reports
Diagnostics: crash logs and performance data
Data Not Linked to Your Identity:
Anonymized and aggregated occupancy analytics
Statistical product improvement data
Data Used to Track You:
Ceveon does not use data collected in this App to track users across third-party apps or websites for advertising purposes.
App Tracking Transparency (ATT):
If any future update introduces cross-app tracking, an explicit ATT prompt will be presented. You may update your preference at any time via iOS Settings &rt; Privacy & Security &rt; Tracking.
AI / Machine Learning Disclosure:
The Ceveon platform uses machine learning models for occupancy detection and vital sign analysis, operated by Ceveon and its contracted cloud infrastructure providers. No personal data is transmitted to general-purpose third-party AI services without your knowledge and consent.
Account Deletion:
Users may request full account deletion via: App &rt; Settings &rt; Account and Security &rt; Delete Account, or by contacting info@ceveon.com. Deletion results in permanent removal of associated personal data subject to applicable legal retention requirements.
13. Google Play Store — Additional Disclosures
The following disclosures support the accuracy of Ceveon's Data Safety section on Google Play, as required by Google Play Developer Policy.
Data Shared with Third Parties:
Limited device and usage analytics may be shared with cloud infrastructure providers acting as processors under contract. No personal data is shared with third parties for advertising, marketing, or behavioral tracking.
Data Collection Summary:
Name and email address: collected, linked to identity, encrypted, not shared with advertisers
Phone number: collected for account and support purposes, not shared with advertisers
Payment data: collected and processed via third-party PCI-DSS compliant providers
Health and biometric data: collected, linked to identity, encrypted, not shared externally
Location (facility-level and zone): collected, linked to identity, not shared with advertisers
Device identifiers: collected for authentication, device management, and diagnostics
App interactions and usage data: collected in aggregate for product improvement
Crash and diagnostic data: collected for performance and stability improvement
Security Practices:
Data encrypted in transit (TLS 1.2+)
Data encrypted at rest (AES-256)
Users can request deletion of their data
Committed to following Google Play security best practices
Android Permission Justifications:
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION: associates device with correct facility network zone and supports geo-fence automations; not stored or tracked continuously
INTERNET: required to sync sensor data, occupancy events, and dashboard content with Ceveon cloud services
CAMERA: required for QR code scanning to pair Smart Devices; activated only on user initiation
RECEIVE_BOOT_COMPLETED: restores alert and notification services after device restart
BLUETOOTH / BLUETOOTH_SCAN / BLUETOOTH_CONNECT: discovers and configures Smart Devices via Bluetooth; activated only during device pairing and management
READ_EXTERNAL_STORAGE / WRITE_EXTERNAL_STORAGE: caches app data, crash logs, and user-uploaded support content
POST_NOTIFICATIONS: delivers real-time occupancy alerts, device status events, and care notifications
Additional permissions may be requested as the platform expands. Each will be disclosed and justified prior to collection.
14. SMS Communications
14.1 Purpose
Ceveon uses SMS messaging strictly for customer support and technical assistance including troubleshooting and service-related updates. SMS is not used for marketing or promotional purposes.
14.2 Consent
Consent to receive SMS messages is not a condition of purchase or use of the Services. Opt-in is required before any SMS messages are sent.
14.3 Message Frequency and Fees
Message frequency varies based on your support needs. Message and data rates may apply depending on your mobile carrier plan.
14.4 Opt-Out
Reply STOP to any message to opt out at any time. Reply HELP for assistance. You may also email info@ceveon.com to be removed.
14.5 SMS Data
We collect your mobile phone number and SMS message content solely to provide customer support. Mobile opt-in data and consent are never shared with third parties for marketing or promotional purposes under any circumstances.
15. Cookies and Tracking Technologies
The Ceveon App and associated web platforms may use:
Necessary cookies: required for core platform functionality including authentication, session management, and security
Analytics cookies: used with your consent to help us understand platform usage and improve the experience
Cookie preferences may be managed via your browser settings or the cookie consent banner at www.ceveon.com. Full details: www.ceveon.com/cookies.
16. Third-Party Services and Integrations
The Ceveon App may connect with third-party platforms, EHR systems, facility management software, and other external services. This Policy does not govern those third parties. We encourage review of each third party's privacy policy before connecting.
Ceveon does not use third-party advertising SDKs or behavioral tracking tools within the App.
Where we integrate with third-party platforms (e.g., Apple Health, Google Home, facility EHR systems), data sharing is limited to what is necessary for the integration and is subject to your explicit consent.
17. Automated Decision-Making and Profiling
Ceveon does not use automated algorithms or AI profiling to make decisions that produce legal or similarly significant effects on users or residents. Machine learning models are used solely for occupancy detection, movement analysis, and operational insights — not for automated individual decision-making with significant consequences.
18. Notice to International Users
Ceveon is based in Miami, Florida, United States. If you access or use the Services from outside the United States, your information will be transferred to and processed in the U.S. in accordance with this Policy and applicable law.
For EEA and UK users, transfers are made using Standard Contractual Clauses or equivalent safeguards. For details, contact info@ceveon.com. Ceveon will comply with applicable data localization requirements where mandated.
19. Changes to This Privacy Policy
We may update this Policy to reflect changes in our data practices, product features, or applicable law. Material changes will be communicated via:
In-app notification
Email to the address associated with your account
Prominent notice on www.ceveon.com
Notice will be provided at least 30 days before material changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
20. Contact Us
For privacy inquiries, rights requests, data concerns, or to request a Business Associate Agreement (BAA):
Ceveon, Inc.
Attn: Privacy Officer
Miami, Florida, United States
Email: info@ceveon.com
Support: support@ceveon.com
Website: www.ceveon.com
Phone: [INSERT PHONE NUMBER]
For GDPR inquiries, our EU Representative (if applicable): [INSERT EU REPRESENTATIVE CONTACT]
We respond to all verifiable requests within 30 days of receipt. You may also access, correct, or delete your data directly through App &rt; Settings &rt; Privacy Settings.
IMPORTANT: This document integrates requirements from Apple App Store Guidelines, Google Play Developer Policy, GDPR, CCPA/CPRA, HIPAA, COPPA, applicable U.S. state privacy laws, and Ceveon's existing privacy documentation. Fields marked [INSERT] must be completed before publication. This is not legal advice. Review by qualified legal counsel is strongly recommended, particularly regarding HIPAA Business Associate obligations, state-specific requirements, and evolving regulatory requirements in jurisdictions where Ceveon operates.
© 2026 Ceveon Inc. All rights reserved. | Miami, Florida, United States