Privacy Policy — MyISA Application
Last updated: 15 September 2026
This policy applies to the MyISA mobile application, available on Google Play (package care.mintt.myisa.b2b) and on the App Store. It supplements the mintt.care website privacy policy, which only covers the website.
1. Who we are
The MyISA application is published by:
MintT SA — Medical Intelligent Technologies, a public limited company (société anonyme) under Belgian law
- Registered office: Avenue Louise 251, 1000 Brussels, Belgium
- Operating office: Quai Paul Verlaine 2, bte 2, 6000 Charleroi, Belgium
- Company / VAT number: BE0544.636.885 (RPM Brussels)
- Contact: contact@mintt.care — +32 (0)2 319 53 39
- Privacy: privacy@mintt.care
- Data Protection Officer (DPO): The Privacy Office, Hochstrasse 81, 4700 Eupen, Belgium — DPO@mintt.care
The application is published on Google Play and the App Store under the developer account Franck Casado, on behalf of MintT SA. For any question about your data, please contact MintT SA using the details above.
2. Who is the application for?
MyISA is a professional application. It is reserved for authorised staff of MintT’s client facilities (nursing homes, care facilities, etc.) that use the ISA detection solution: monitoring rooms equipped with sensors, and receiving and handling alerts.
You cannot sign up yourself: accounts are created by the facility, or by MintT at its request, under a contract. The application is not intended for children.
3. MintT’s role: processor on behalf of the facility
For data processed through MyISA, MintT acts as a processor within the meaning of Article 28 of the GDPR, on behalf of the client facility, which is the data controller. This processing is governed by the contract with the facility.
In practice:
- the facility determines the purposes of the processing: resident safety, organisation and traceability of care;
- MintT processes data only on the documented instructions of the facility;
- MintT helps the facility respond to requests from individuals exercising their rights (see section 10).
4. Data processed
4.1 Data about staff users
- Account: first name, last name, username, email address, role(s), facilities and room groups the user can access; where applicable, a phone number for receiving alerts by text message or call.
- Notification preferences: types of alerts followed, per facility and room group.
- Traceability: viewing and downloading of alert videos, annotations and follow-up of alerts, with date and time.
- Technical data: the device’s push notification subscription identifier, application version, operating system.
Purposes: authentication, role-based access management, delivering alerts to the right people, traceability of interventions, security and support.
4.2 Data about residents
- Room and room label, room group, facility.
- Alerts: type of event detected (fall, bed exit, prolonged absence, etc.), date and time, status, staff follow-up and annotations, statistics.
- Alert video sequences: short sequences generated by the sensor installed in the room from its infrared and depth images, rendered with colour masks that distinguish the person, the floor and the bed. No colour camera is used. These sequences allow staff to check the situation and intervene.
This data may constitute data concerning health (Article 9 of the GDPR). It is processed under the responsibility of the facility and hosted in France with hosting providers, including a provider certified for health data hosting (HDS) (see section 7).
The application contains no advertising, no advertising trackers and no audience measurement tools. Data is never sold or used for commercial purposes.
5. Permissions requested on the device
| Permission | Use | Data collected by MintT? |
|---|---|---|
| Notifications | Receive alerts in real time | Push subscription identifier only |
| Camera | Scan a sensor’s barcode when installing or replacing it | No: the image is neither stored nor transmitted |
| Face ID / fingerprint | Quick unlocking of the application | No: verification is performed by the device’s operating system; MintT never has access to biometric data |
| Storage / files | Save a video or an export on the device, only at the user’s request | No. The saved file is then subject to the facility’s own rules |
| Bluetooth | Configure a nearby sensor (installation, maintenance) | No |
| Location | Android 11 and earlier only: the operating system requires it to scan for Bluetooth devices. Not requested on iOS or on Android 12 and later | No: no location is read, stored or transmitted |
You can withdraw these permissions at any time in your device settings. Some features will then no longer be available, in particular receiving alerts without notifications.
6. Legal basis
Processing carried out by MintT is based on the performance of the contract with the client facility and on its instructions as data controller.
The legal basis for processing residents’ data is determined by the facility, as data controller, as part of its care mission.
7. Hosting, sub-processors and transfers
| Provider | Role | Data location |
|---|---|---|
| Ecritel (Clichy, France) | Data hosting, including alert captures, HDS certified | France (EU) |
| OVHcloud | Hosting of the ISACore platform (servers, database, video storage) | Strasbourg, France (EU) |
| DigitalOcean, LLC | Hosting of the legacy platform, currently being migrated to the ISACore platform in France | Amsterdam, Netherlands (EU) |
| OneSignal, Inc. | Sending push notifications. Data processed: username, device subscription identifier, facility and alert preferences, notification content (alert type, room label, time) | United States |
| Twilio Inc. | Sending alerts by text message and voice call, when the facility enables these channels. Data processed: phone number, message content (alert type, room label, time) | United States |
| Apple / Google | Technical delivery of notifications (APNs / FCM), application distribution | According to their terms |
For transfers to the United States, MintT relies on appropriate safeguards within the meaning of Chapter V of the GDPR: the standard contractual clauses adopted by the European Commission, included in these providers’ data processing agreements, and, where applicable, their certification under the EU–US Data Privacy Framework.
Notifications contain no resident names, images or videos. As room labels are defined by the facility, MintT recommends not including residents’ names in them.
Sub-processors are authorised by the facility in accordance with the contract.
8. Retention period
Contracts with facilities are fixed-term and renewable.
- During the contract: data (accounts, alerts, video sequences, history) is kept for as long as necessary to provide the service and ensure traceability of care, in accordance with the facility’s instructions.
- End of the contract: in accordance with MintT’s general terms and conditions, user accounts and associated data are deleted 6 months after the end of the contract, unless the facility instructs otherwise (return of data) or a legal retention obligation applies.
- Technical capture data: raw data transmitted by the sensors is deleted within 7 days at most. Technical information linking a capture to a room or facility is removed from working copies after 21 days.
- Notification identifier: kept until unsubscription (sign-out, disabling notifications or uninstalling the application).
9. Security
- Encrypted communications (HTTPS/TLS) between the application and the servers.
- Token-based authentication, with the token stored in the device’s secure storage (Keychain / Keystore). Optional biometric unlocking.
- Automatic sign-out after a period of inactivity, configurable per facility.
- Access to videos restricted to authorised staff: access depends on the user’s role on the room group concerned and on the video option subscribed by the facility. Each playback uses a temporary link valid for 2 hours at most, and every view or download is logged with the user, facility and room.
- Data segregation by facility and by role.
- Health data hosted with an HDS-certified provider, in France.
- ISO 27001 certification in progress.
10. Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction, objection and data portability.
As MintT is a processor, please address your request primarily to your facility (the data controller). You can also write to privacy@mintt.care or to the DPO (DPO@mintt.care): MintT will forward your request to the facility and help it respond.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be) or with the supervisory authority of your country.
11. Deleting your account and data
MyISA accounts are managed by the facility. To delete your account and the associated data:
- Ask your facility’s administrator, who can deactivate or delete your account; or
- Send an email to privacy@mintt.care from the address linked to your account, stating the name of your facility. MintT will handle the request together with the facility within one month at most.
Deletion covers your personal user data (account, preferences, notification identifier). The record of actions taken on residents’ alerts may be kept where the facility is required to retain it for traceability of care; it is then kept for the period set out in section 8.
If you make no request, accounts are deleted 6 months after the end of the facility’s contract (section 8).
12. Changes
This policy may change, for example when features are added or a provider changes. The date of the last update is shown at the top of this page. In the event of a significant change, users are informed in the application or by their facility.
13. Contact
MintT SA — Avenue Louise 251, 1000 Brussels, Belgium Privacy: privacy@mintt.care — DPO: DPO@mintt.care — +32 (0)2 319 53 39