IyàCare End-User License, Copyright, and Privacy Policy Agreement

Comprehensive policy for maternal healthcare platform operations

1. Introduction to the Agreement

Purpose and Scope

This agreement governs the use of the IyàCare platform, including its web application, mobile interfaces, IoT devices, and any related services. This policy is designed to ensure the safe, ethical, and effective operation of our maternal healthcare platform in resource-constrained settings.

IyàCare is a multi-faceted system involving hardware (IoT), software (frontend/backend), and distributed ledger technology (blockchain). This comprehensive framework ensures all components and interactions fall under the same legal and ethical standards.

Acceptance of Terms

By accessing, using, or registering for the IyàCare platform, you explicitly accept and agree to be bound by these terms. This acceptance establishes legal enforceability and ensures that Community Health Workers (CHWs) and patients acknowledge the terms before engaging with sensitive health data collection and sharing.

2. End-User License Agreement (EULA) & Platform Use

License Grant

IyàCare grants you a limited, non-exclusive, non-transferable, revocable license to use the platform for its intended purpose: maternal healthcare monitoring, risk assessment, and record-keeping. For Community Health Workers, this license covers professional duties within the scope of healthcare work.

Restrictions on Use

You are prohibited from:

  • Unauthorized copying, modification, reverse engineering, or distribution of the platform
  • Commercial exploitation outside of authorized healthcare activities
  • Using the platform for illegal activities or transmitting harmful content
  • Interfering with platform operation or attempting to exploit vulnerabilities
  • Tampering with blockchain data integrity or security measures

User Responsibilities

As a user, you are responsible for:

  • Maintaining confidentiality of login credentials
  • Ensuring accuracy of data input (patient demographics, vital signs)
  • Proper handling and care of provided IoT devices
  • Compliance with applicable laws and ethical guidelines for patient care
  • Following data privacy protocols and patient consent procedures

Offline Functionality

While the platform supports offline data collection, you must ensure devices are periodically connected to the internet for data synchronization. Data processed offline may not immediately reflect the latest risk assessments or be fully recorded on the blockchain until synchronization occurs.

SMS Alerts

By providing a mobile number, patients consent to receive SMS alerts related to health status, appointments, or critical health information from IyàCare. Users may opt out at any time by replying "STOP" to any message or contacting our support team.

3. Copyright and Intellectual Property

Platform Ownership

IyàCare retains all rights, title, and interest in the platform, including software, design, predictive models, AI algorithms, blockchain implementation, and underlying technology. This protects our significant investment in developing the integrated AI-IoT-blockchain solution.

User-Generated Content

Users grant IyàCare a license to use data they input for operating, maintaining, improving, and analyzing the platform. This data is processed in anonymized or aggregated form where possible, always in compliance with this Privacy Policy. This license is essential for risk assessment, blockchain storage, and predictive model refinement.

4. Privacy Policy - Data Handling

Data Collection

Types of Data Collected:

  • Demographic Data: Patient age, location, pseudonymized unique ID
  • Vital Signs Data: Blood pressure, temperature, heart rate (IoT devices or manual entry)
  • Health Records Data: Pregnancy history, medical conditions, medications, care notes
  • Predictive Outcomes: AI-generated risk scores and assessments
  • Usage Data: Platform interaction patterns, feature access, timestamps

Methods of Collection:

  • Manual input by Community Health Workers
  • Automated collection from connected IoT devices
  • System-generated data from predictive models

Data Usage and Processing

Primary Purpose:

  • Providing maternal healthcare services and continuous monitoring
  • Predictive risk assessment and early intervention
  • Facilitating care coordination between healthcare providers
  • Maintaining secure, immutable health records

Secondary Purpose:

  • Platform improvement and optimization
  • Public health research (anonymized/aggregated data only)
  • Population health reporting and analytics

Data Sharing

Authorized Sharing:

  • Healthcare Providers: Authorized doctors, nurses, and CHWs directly involved in patient care
  • Service Providers: Essential third-party services (Firebase, SMS gateway, cloud hosting) under strict data processing agreements
  • Blockchain Network: Critical, non-personally identifiable health events recorded on Ethereum for immutability
  • Legal Requirements: Disclosure when required by law or to protect rights and safety

Consent Requirements

Explicit and Informed Consent:

  • Explicit consent required for collection, processing, and sharing of sensitive health data
  • Consent must be freely given, specific, informed, and unambiguous
  • Right to withdraw consent at any time with clear instructions
  • Separate consent processes for clinical trials or research participation

Accessible Consent:

  • Consent forms provided in clear, simple language
  • Formats suitable for low-literacy populations
  • Local language translations available
  • Verbal explanations and visual aids when needed

Data Retention

  • Health records retained for duration of care plus legally mandated period
  • Usage data retained for shorter analytical periods
  • Blockchain data is immutable by design
  • Associated off-chain data follows standard retention policies

Data Security

We implement comprehensive security measures:

  • End-to-end encryption for data in transit and at rest
  • Multi-factor authentication and access controls
  • Regular security audits and penetration testing
  • Secure coding practices and vulnerability management
  • Firebase and Ethereum blockchain security features

User Rights

You have the following rights regarding your data:

  • Right to Access: Request copies of your personal and health data
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of personal data (noting blockchain immutability limitations)
  • Right to Data Portability: Receive data in structured, machine-readable format
  • Right to Object: Object to certain types of data processing

5. Limitations of Liability & Disclaimers

No Medical Advice

IyàCare is a technological tool for monitoring and risk assessment. It does not provide medical advice, diagnosis, or treatment. Users must consult qualified healthcare professionals for all medical decisions. The platform supports but does not replace human medical expertise.

Accuracy of Information

We disclaim responsibility for inaccuracies arising from user-entered data, IoT sensor limitations, or external factors affecting data transmission. This acknowledges real-world challenges of data collection in low-resource settings.

Service Availability

While we strive for high availability and include offline functionality, we cannot guarantee uninterrupted or error-free service due to factors beyond our control, including internet outages and hardware failures.

Third-Party Services

IyàCare integrates with third-party services (mobile networks, Firebase, etc.). We are not responsible for the privacy practices or content of these external services.

6. Governing Law & Dispute Resolution

This agreement is governed by applicable healthcare and data protection laws. Disputes will be resolved through arbitration before litigation, providing a clear framework for addressing disagreements.

7. Changes to the Agreement

IyàCare reserves the right to modify this agreement. We will notify users of significant changes, and continued use after notification constitutes acceptance of new terms. This ensures the policy remains current with platform evolution and legal requirements.

8. Contact Information

For questions about this policy, to exercise your rights, or report concerns:

  • Email: privacy@iyacare.site
  • Data Protection Officer: dpo@iyacare.site
  • Support: support@iyacare.site
  • Website: www.iyacare.site

Last Updated: 7/28/2025
Effective Date: 7/28/2025
This comprehensive policy demonstrates our commitment to ethical healthcare technology deployment and user privacy protection in maternal healthcare settings.