Privacy Policy of HeartFocus
Privacy Policy of HeartFocus
Effective Date: September 10, 2026
Version: 3.0
At DESKi, the security of your personal data is our primary commitment. Before using HeartFocus via the HeartFocus Portal (connectivity/communication platform), the HeartFocus App (medical device), or HeartFocus Link (educational non-medical software tool) (together "HeartFocus"), please read this Privacy Policy ("the Policy") which explains how we process your personal data collected via HeartFocus (hereinafter referred to as "Data").
"HeartFocus" covers three offerings with different data practices:
- HeartFocus Portal and probe-based HeartFocus App: Use a user account and sign-in, process profile/contact data, and may involve payment processing.
- HeartFocus Link: An educational application used with cart-based ultrasound systems. LINK has no user account or sign-in, is activated by a one-time code provisioned to the customer organization, and involves no in-app payment.
Where a section below applies only to a specific offering, this is indicated. Sections on accounts, sign-in, and payments do not apply to HeartFocus Link.
By Data, we mean any information that identifies or relates to a particular person directly or indirectly, including information designated as personal data, personal information, or Data Principal data under applicable data protection laws, rules, or regulations (including the EU GDPR, US State Privacy Laws, and the Indian Digital Personal Data Protection Act, 2023).
The Policy details how DESKi processes your Data when you use HeartFocus ("the Services"). ThisPolicy applies to your use of the Services and explains the legal bases upon which we collect, use, and share your Data.
In particular, this Policy does not cover the data processing practices of third-party devices connected to the Services, such as the heart imaging probe provided by an external manufacturer. The processing of data by such devices is subject to separate privacy policies issued by the respective entities responsible for their operation and management.
I. General Conditions for Processing Your Data
Who is responsible for your Data?
The company DESKi, a Simplified Joint Stock Company registered under number 818145211 and located at 2-8, 2 PLACE DE LA BOURSE, 33000 BORDEAUX - France, trading name as DESKi ("DESKi"), acts as the Data Controller (under EU GDPR) and Data Fiduciary (under India's DPDPA 2023) when you use the Services.
For any information related to the processing of your Data, you can contact DESKI’s Data Protection Officer / Grievance Officer at: dpo@deski.ai.
Role Responsibilities by Product
- HeartFocus Portal: DESKi is the Data Controller / Data Fiduciary for User Profile and Contact Data (used for authentication) and Technical and Navigation Data collected via the Portal.
- HeartFocus App: DESKi is the Data Controller / Data Fiduciary for Technical and Navigation Data (crash diagnostics via Sentry, usage analytics via Matomo). DESKi is neither Controller nor Processor / Data Fiduciary for any clinical or exam content (ultrasound video, images, exam clips) or Protected Health Information (PHI) generated within the App; this content remains exclusively on the User's device and is never transmitted to DESKi.
- HeartFocus Link: DESKi is the Data Controller / Data Fiduciary for activation codes, installation identifiers, license status, B2B contact data, and Technical and Navigation Data. DESKi is neither Controller nor Processor for clinical content, which is processed and stored exclusively on infrastructure operated by the customer healthcare organization.
What Data is Processed and Why?
If your data was provided to us by your employer or healthcare organization holding a HeartFocus Link license, this notice serves as disclosure under Article 14 GDPR and applicable global laws. The categories of data are limited to your professional contact details and employing organization name.
Legal Basis for Processing
DESKi processes your Data under the following lawful bases:
- Performance of Contract (Art. 6(1)(b) GDPR / Lawful Use DPDPA): Processing User Profile Data to authenticate your account and deliver the Services.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing Technical and Navigation Data for system stability, security, and service improvement.
- Consent (Art. 6(1)(a) GDPR / Section 6 DPDPA): For optional analytics (Matomo) or direct marketing where required by law.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Financial, tax, and regulatory compliance obligations.
Automated Processing (AI-Assisted Image Guidance)
The HeartFocus App and Link include an AI feature providing real-time image-quality guidance. This feature supports clinician judgment and does not make automated decisions with legal or significant effects (Art. 22 GDPR). AI inference runs entirely on the local device; DESKi does not receive inputs or outputs.
Payments
DESKi uses Stripe to process payments for purchases made via the HeartFocus Portal. When making a purchase, billing details and transaction metadata are sent directly to Stripe. DESKi does not store full credit card numbers on its systems.
How is Your Data Protected?
DESKi implements technical and organizational security measures including:
- Encryption: TLS 1.2 for data in transit and AES-256 for data at rest.
- Strict Access Control: Role-based, need-to-know permissions.
- Continuous Monitoring: Regular production security reviews and vulnerability scans.
- Vetted Service Providers: Third-party vendors are contractually bound through Data Processing Agreements (DPAs).
In the event of a personal data breach affecting your Data, DESKi will notify competent supervisory authorities (including the CNIL in France and the Data Protection Board of India) and affected individuals without undue delay where required by applicable law.
Data Retention
- User Account Data: Retained for the duration of the contractual relationship and up to 2 years after last activity to facilitate account reactivation, or up to 5 years for legal claims under French statutory limitation periods.
- Technical & Navigation Data: Retained for a maximum of 25 months from your last connection.
- Financial & Billing Data: Retained for 10 years from the transaction date per Article L.123-22 of the French Commercial Code. Fraud prevention logs are retained for 13 to 15 months.
- HeartFocus Link Identifier Data: Retained for the commercial contract duration and 5 years thereafter.
II. Your Rights Regarding the Processing of Your Data
Summary of Global Data Principal / Data Subject Rights
Depending on your jurisdiction (EU, India, US), you may exercise the following rights by contacting dpo@deski.ai:
- Right of Access / Right to Know: Request confirmation of processing, copies of your personal data, and details regarding third-party disclosures.
- Right to Rectification / Correction: Request correction of inaccurate or incomplete personal information.
- Right to Erasure / Deletion: Request erasure of your data when processing is no longer necessary or consent is withdrawn.
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests or request restriction of processing.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Nominate (India - DPDPA): Nominates an individual to exercise your data protection rights in the event of death or incapacity.
- Right to Grievance Redressal: Access simple and effective grievance redressal mechanisms through our Grievance Officer.
DESKi will respond to valid data subject requests within 30 days (or within timelines prescribed by local laws such as 45 days for US requests).
Children's Privacy
The Services are not intended for minors under 18 years of age. DESKi does not knowingly collect or process personal data of children under 18 without verifiable parental consent where required by applicable laws (including Section 9 of India's DPDPA). If you become aware that a minor has provided personal data, contact dpo@deski.ai for prompt deletion.
III. Conditions for Sharing and Transferring Your Data
Data Processors and Service Providers
Your profile data is accessible only to authorized DESKi personnel. Technical diagnostic and navigation data may be shared with trusted data processors acting strictly under DESKi’s instructions:
- Sentry.io: Application crash monitoring and error logs.
- Matomo Cloud: Anonymized product analytics (subject to opt-in/opt-out preferences).
- Google Analytics: Website usage analytics (subject to cookie consent).
All analytics tools are configured to automatically strip and exclude clinical images, free-text inputs, and health metadata at the point of capture on your device.
Do Not Sell or Share Personal Information
DESKi does not sell personal information or share personal data for cross-context behavioral advertising.
International Data Transfers
When transferring personal data outside the European Economic Area (EEA) or India, DESKi ensures adequate safeguards are established:
- Transfers from EEA: Secured via European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs).
- Transfers from India: Executed in full compliance with Section 16 of the DPDPA 2023, ensuring data is not transferred to restricted jurisdictions published by the Central Government of India.
IV. Specific Regional Regulatory Compliances
1. European Union (GDPR)
DESKi complies with Regulation (EU) 2016/679 (GDPR). EU residents may lodge a complaint with their local supervisory authority or the French Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr.
2. United States Compliance
HIPAA Notice
DESKi is not a Covered Entity under HIPAA. Clinical ultrasound images and PHI remain exclusively on the user’s local device or customer infrastructure. DESKi's obligations regarding incidental access to PHI are governed by Business Associate Agreements (BAAs) executed with customer healthcare entities.
US State Privacy Laws (CCPA / CPRA / VCDPA / CPA / CTDPA / UCPA)
US residents hold rights to know, delete, correct, and opt out of personal data selling/sharing. Requests can be submitted to dpo@deski.ai. DESKi will not discriminate against users exercising their legal privacy rights.
3. India Compliance (Digital Personal Data Protection Act, 2023 - DPDPA)
For users residing in India:
- Data Roles: DESKi acts as a "Data Fiduciary" and the user is recognized as a "Data Principal."
- Consent Notice: Personal data processing is based on explicit, free, specific, informed, unconditional, and unambiguous consent, or designated lawful uses under the DPDPA.
- Right to Nominate: Indian residents may submit a written nomination designating an individual to exercise data rights upon death or incapacity by emailing dpo@deski.ai.
- Grievance Redressal Officer: For unresolved queries, contact our Grievance Officer at dpo@deski.ai.
- Escalation to DPBI: If your grievance is not resolved by our Grievance Officer within 30 days, you have the statutory right to file a complaint directly with the Data Protection Board of India (DPBI).
- Language Access: Pursuant to Section 5(2) of the DPDPA, this notice and consent requests are available in English and can be provided in any of the 22 languages specified in the Eighth Schedule to the Constitution of India upon request to dpo@deski.ai.
V. Cookies and Web Analytics
DESKi uses essential cookies required for system navigation, security (Google reCAPTCHA), and consent management (CookieYes). Optional third-party cookies (Google Analytics) are stored only after active consent via our consent banner.
VI. Updates to this Policy and Contact Information
DESKi reserves the right to update this Policy to reflect technical or legal changes. Users will be notified of material changes upon their next connection or via email prior to implementation.
Contact & Grievance Address:
DESKi (Data Protection Officer & Grievance Officer)
2-8, 2 PLACE DE LA BOURSE, 33000 BORDEAUX - France
Email: dpo@deski.ai

