Privacy Policy
Request to Delete Data
Gray Matters Alliance, LLC
Mobile App & Platform Privacy Policy
​
Effective Date: August 15 2025 Version: 3.0 Last Updated: July 6 2026
Applies To:
-
MyCompass™ App — Apple App Store (End Users)
-
Compass Care Calling™ App — Apple App Store & Google Play (Authorized Users)
-
Compass Care Alerts™ App — Apple App Store & Google Play (Authorized Users)
-
MyCompass™ Web Portal — secure browser-based access (Authorized Users)
-
Nora Caregiver Intelligence™ — AI-enabled caregiver support feature (see Section 6)
​
IMPORTANT SAFETY NOTICE
The Services provide supportive monitoring, reminders, and notifications. They are not a medical device, are not a personal emergency response system (PERS), and are not a guaranteed, real-time emergency-response service. The Services are not a substitute for 911, emergency services, or professional medical, clinical, or caregiving judgment. Alerts and notifications depend on device, network, sensor, power, and configuration conditions and may be delayed, incomplete, or undelivered. In an emergency, contact 911 or your local emergency services immediately.
Our Promise: We Will Never Sell or Market Your Information
The people we serve trust us with some of their most sensitive information. We treat that trust as the foundation of everything we do. We make this promise plainly:
• We will never sell, rent, or trade your information — including your PHI and any de-identified data derived from it — to anyone, for any price.
• We will never share your information with advertisers or data brokers, and we will never use it for advertising or marketing.
• We will never let a third party use your information for that third party’s own purposes.
• We will never use your information to train advertising or commercial AI models.
We use information only to provide your services, keep you safe, obtain payment from your health plan for services we actually delivered, run our organization responsibly, and comply with the law. We use de-identified data only for our own quality improvement, safety, accessibility, and non-commercial research — never for sale, licensing, or advertising.
This promise binds not only GMA today but anyone who may operate the Services in the future. If GMA is ever part of a merger, acquisition, financing, reorganization, or sale of assets, your information will remain protected under this same commitment, and any successor will be contractually required to honor it.
This is not a marketing statement. It is a commitment we intend to be held to.
1. Purpose and Scope
This Privacy Policy (“Policy”) describes how Gray Matters Alliance, LLC (“GMA,” “we,” “our,” or “us”) collects, uses, discloses, and protects personally identifiable information (“PII”) and protected health information (“PHI”) when you use any of GMA’s mobile applications, the MyCompass Web Portal, and the connected services that make up the MyCompass System (collectively, the “Services”).
The Services include:
-
MyCompass™ App — used by individuals receiving services (“End Users”) under GMA’s support programs;
-
Compass Care Calling™ App — used by guardians, legal representatives, and authorized professionals (“Authorized Users”) to communicate with End Users;
-
Compass Care Alerts™ App — used by Authorized Users to receive safety-related notifications;
-
MyCompass™ Web Portal — secure browser-based access used by Authorized Users; and
-
Nora Caregiver Intelligence™ — GMA’s AI-enabled caregiver support feature (see Section 6).
These applications and services are part of GMA’s MyCompass System™, a comprehensive, HIPAA-compliant remote support and assistive-technology platform that includes the mobile and web apps; secure cloud storage and APIs; Nora Caregiver Intelligence; on-premises home-support hardware; Apple HealthKit and HomeKit integrations (where enabled); approved third-party Internet-of-Things (IoT) devices and sensors; Mobile Device Management (MDM); and optional content-filtering and monitoring tools. The administrative, physical, and technical safeguards described in Section 8 apply to every component of the MyCompass System, including any on-premises hardware.
1.1 GMA’s Regulatory Status and Role
GMA is an enrolled government-healthcare provider (including Medicaid and, where applicable, other government health programs) and a Covered Entity under the Health Insurance Portability and Accountability Act (“HIPAA”). GMA acts as a Covered Entity for the services it furnishes directly to End Users. In certain arrangements, GMA may instead perform functions on behalf of another covered entity (for example, a provider agency, managed-care organization, or health plan), in which case GMA acts as a Business Associate and the applicable Business Associate Agreement (“BAA”) governs GMA’s use and disclosure of information for those functions. Where GMA acts as a Business Associate, this Policy applies only to the extent consistent with that BAA and the direction of the responsible covered entity.
1.2 Relationship to the Notice of Privacy Practices and Other Terms
This Policy is a general notice of GMA’s privacy practices and operates alongside GMA’s Notice of Privacy Practices (“NPP”), which is provided separately as required by 45 CFR § 164.520. Where this Policy and the NPP address the same subject, the NPP governs GMA’s formal HIPAA obligations. This Policy is also subject to GMA’s End User License Agreement and any applicable service or Terms of Use agreement; where those agreements address matters such as liability, dispute resolution, and acceptable use, those agreements govern those topics. See Section 14.
1.3 Acceptance of This Policy
Where an End User has the legal capacity to do so, that End User may review and accept this Policy. Where an End User is a minor or an adult who lacks legal capacity, this Policy is reviewed and accepted on the End User’s behalf by the End User’s legally authorized representative, and use of the Services by such an End User is not, by itself, acceptance of these terms by that End User. By accepting this Policy, or by accepting it on behalf of an End User you are legally authorized to represent, you acknowledge that you have read, understood, and agreed to it.
2. Definitions
The following definitions apply throughout this Policy and govern all interactions with the Services.
2.1 “Services,” “Apps,” or “Applications.” The MyCompass App, the Compass Care Calling App, the Compass Care Alerts App, the MyCompass Web Portal, Nora Caregiver Intelligence, and the connected components of the MyCompass System owned and operated by Gray Matters Alliance, LLC.
2.2 “MyCompass System.” The integrated, HIPAA-compliant infrastructure operated by GMA, including mobile and web apps, cloud-based backend, secure APIs, Nora Caregiver Intelligence, MDM tools, on-premises home-support hardware, Apple HealthKit/HomeKit integrations where enabled, and approved third-party IoT devices. This system supports remote support services, care planning, device management, alerting, and communications for individuals served by GMA.
2.3 “Gray Matters Alliance” or “GMA.” Gray Matters Alliance, LLC, the legal entity responsible for developing, maintaining, and operating the Services, and the primary data steward for information processed through the Services. GMA’s regulatory role is described in Section 1.1.
2.4 “Protected Health Information” (PHI). As defined by HIPAA (45 CFR § 160.103), individually identifiable health information transmitted or maintained in any form that relates to an individual’s health or condition, the provision of health care, or payment for health care, and that identifies the individual or can reasonably be used to identify them.
2.5 “Personally Identifiable Information” (PII). Information that can be used on its own or with other information to identify, contact, or locate a person, including (but not limited to) full name, address, email, phone number, date of birth, IP address, and device identifier.
2.6 “End User.” The individual receiving remote support services through GMA, typically using the MyCompass App directly. End Users may include persons with intellectual, developmental, or physical disabilities, aging adults, or others receiving waiver or clinical services. An End User may require or authorize a legally authorized representative to manage access on their behalf.
2.7 “Authorized User.” An individual legally authorized to access information about an End User, including legal guardians; parents or spouses with power of attorney; and case managers, clinicians, or care providers with documented consent or contract authority. An Authorized User’s access is limited to the scope of that documented legal authority. Authorized Users may use the Compass Care Calling App, the Compass Care Alerts App, or the Web Portal to fulfill caregiving or professional duties under HIPAA-compliant agreements.
2.8 “Legally Authorized Representative.” A legal guardian, conservator, parent or custodian (where permitted by law), health-care power of attorney, agent under a supported-decision-making agreement, or other person or entity authorized under applicable state law to make decisions or grant authorizations on behalf of an End User, within the scope of that authority.
2.9 “Consent” or “Authorization.” Documented permission by the End User or their Legally Authorized Representative, as required under 45 CFR § 164.508, for the collection, use, or disclosure of PHI or PII by GMA and its Business Associates.
2.10 “Business Associate.” Any individual or entity that performs functions involving PHI on behalf of GMA, pursuant to a formal Business Associate Agreement (BAA) under HIPAA. This may include cloud-hosting providers, AI infrastructure providers, communication vendors, IoT integration partners, billing and revenue-cycle vendors, clearinghouses, and customer-support services.
2.11 “Device Metadata.” Automatically collected technical data related to app or device use, which may include IP address, device operating system, device ID (Apple IDFA or Android AAID), crash logs, and app version and usage patterns.
2.12 “De-Identified Data.” Data stripped of identifiers such that it cannot reasonably be used to identify an individual, in accordance with HIPAA’s de-identification standards (45 CFR § 164.514), using either the Safe Harbor or Expert Determination method.
2.13 “Mobile Device Management (MDM).” Administrative and technical tools used by GMA to secure and support GMA-provided tablets or phones issued to End Users, which may include app-usage restriction, location features (only if authorized), internet filtering, and device-health and compliance monitoring, configured as described in Section 8.5.
2.14 “Emergency Event.” A system-defined incident or condition that may include boundary breaches, periods of inactivity, fall detection, or any safety-related event that triggers an alert within the Compass Care Alerts App or initiates contact through Compass Care Calling. The limitations in the Important Safety Notice above apply to all Emergency Events.
2.15 “Nora Caregiver Intelligence” (“Nora”). GMA’s AI-enabled caregiver support feature, operated by GMA on Amazon Web Services using AWS Bedrock under a Business Associate Agreement. Nora provides decision support only, operates under human oversight, and does not make autonomous clinical or safety determinations. See Section 6.
2.16 “Biometric or Biometric-Derived Data.” Data generated from measurements of an individual’s biological or behavioral characteristics that can be used to identify the individual, and data derived from such measurements, to the extent any such data is processed by the Services. See Section 3.8.
2.17 “Payment and Billing Information.” Information used to verify eligibility, obtain authorization, and submit, document, and adjudicate claims for the Services, including payer and plan identifiers, claim and service records, and related financial information.
2.18 “Connected Platforms and IoT Integrations.” Approved third-party platforms, devices, and sensors that exchange data with the MyCompass System, including Apple HealthKit and HomeKit (where enabled) and approved IoT devices such as medication dispensers, fall sensors, and environmental sensors. Data exchanged with these platforms is governed by Section 11.
3. Information We Collect
GMA collects limited, purpose-driven information to support individualized services, promote safety, and comply with healthcare obligations. Information is collected only when necessary for service delivery or client protection, authorized by the End User or their Legally Authorized Representative, or required by law or regulatory contract. Information may be submitted directly by the user, passively collected via system use, or received from Connected Platforms and third-party integrations under Business Associate Agreements.
3.1 MyCompass App (Apple App Store — End Users)
Designed for individuals receiving remote support services, the MyCompass App collects information to facilitate daily routines, goals, wellness monitoring, and communication. Data collected includes:
-
PII: full name, date of birth, contact information, client ID (if used);
-
Service-Related Data (PHI): support schedules, goal tracking, check-in notes, reminders, emergency contacts and custom alert preferences, and self-notes or feedback;
-
App Interaction Data: page visits, clicks, frequency of logins, and timestamped activities;
-
Device Metadata (via MDM): device type, OS version, IP address, and crash reports;
-
Health Data via Apple HealthKit (only where enabled and authorized): see Section 11.
Sensitive Data Handling. GPS location and microphone/camera access are not collected unless a specific feature requires it and it is explicitly enabled and authorized. Biometric or biometric-derived data is handled only as described in Section 3.8. Except for Nora Caregiver Intelligence (which operates as a care-support feature under Section 6) and security/diagnostic tooling, the MyCompass App does not use tracking cookies, advertising IDs, or analytics SDKs unrelated to medical or care support.
3.2 Compass Care Calling App (Apple + Google — Authorized Users)
Allows Authorized Users to initiate or respond to calls with the End User. Data collected includes caller/recipient identity (display name, linked client ID, authorized-user role); communication metadata, not content (call timestamps, duration, direction, error codes); device metadata (IP address, device ID, OS); and user authentication tokens (secured session IDs).
Note: No call audio or video is recorded or stored. GMA does not access call content. If recording functionality is implemented in the future, it will be enabled only with express authorization, advance notice, a Policy update, and compliance with applicable federal and state wiretap and two-party/all-party consent laws.
3.3 Compass Care Alerts App (Apple + Google — Authorized Users)
Provides real-time event notifications and logs concerning End User safety, based on thresholds defined in the support plan. Data collected includes alert metadata (alert type, timestamp, status, recipient log); authorized-user information (name, role, contact, linked clients); device metadata (push token, OS version, device type); limited HealthKit-derived context where a HealthKit integration is enabled and relevant to an alert; and optional approximate geolocation of the End User only when alert-location monitoring is explicitly enabled by the End User’s Legally Authorized Representative.
Note: Alerts are based on rules configured by authorized parties. No continuous location tracking is performed unless explicitly configured and consented to where legally appropriate. The limitations in the Important Safety Notice apply.
3.4 MyCompass Web Portal (Authorized Users)
The Web Portal provides browser-based access for Authorized Users and may process the same categories of PII, PHI, and authentication data described above, together with browser session data, IP address, and access logs. The same role-based access controls, encryption, and audit logging that apply to the mobile apps apply to the Web Portal.
3.5 Shared System-Level Data (All Services)
The following technical and security-related data may be collected across all Services: user authentication logs and timestamps; password resets or session expirations; MDM status; app and portal version, usage health, and error reporting; and consent-acknowledgment logs (e.g., EULAs and authorization forms).
3.6 Payment and Billing Information
To deliver and obtain payment for the Services, GMA collects and maintains Payment and Billing Information, including payer and plan identifiers, eligibility and authorization data, service and claim records, and related financial information. GMA uses and discloses this information for payment purposes as permitted by HIPAA (see Sections 4.1 and 7.3), and protects it with the safeguards described in Section 8. GMA does not use Payment and Billing Information for advertising, marketing, or profiling.
3.7 Connected Platforms and IoT Integrations
Where the MyCompass System is connected to approved platforms and devices (e.g., Apple HealthKit/HomeKit, smart medication dispensers, wearable or fall sensors), GMA may receive device readings (e.g., medication events, fall detection), status reports (e.g., device disconnected, low battery), and usage or alert history. All such data is received under HIPAA-compliant agreements (or, for Apple HealthKit/HomeKit, handled under Apple’s platform requirements as described in Section 11) and handled in accordance with this Policy.
3.8 Biometric and Biometric-Derived Data
Some assistive features may, where enabled and authorized, process biometric or biometric-derived data (for example, certain access methods or physiologic or behavioral measurements). GMA collects such data only where a feature the End User or their Legally Authorized Representative has enabled requires it, limits it to the minimum necessary, and does not use it for advertising, marketing, or profiling. Where GMA processes biometric or biometric-derived data, GMA: provides notice of the categories collected and the purpose; obtains consent where required by applicable law; protects the data under Section 8; and retains it only as long as needed for the authorized purpose or as required by law, after which it is securely destroyed or de-identified. If a feature that processes biometric data is not enabled, GMA does not collect biometric data through that feature.
3.9 Data Minimization and Least-Privilege Access
GMA enforces HIPAA’s “minimum necessary” standard. No employee, Authorized User, or system administrator may access more data than is required for the delivery of services. All access is logged and monitored.
4. HIPAA Permitted Uses and Basis for Processing
As a Covered Entity, GMA collects, uses, and discloses information only as permitted or required by HIPAA, the HITECH Act, and other applicable U.S. federal and state laws. The following describes the bases on which information from the Services may be processed.
4.1 Treatment, Payment, and Health Care Operations
Under 45 CFR § 164.506, GMA may use and disclose PHI without separate authorization as necessary for treatment, payment, and health care operations, including providing, coordinating, or managing remote support services; facilitating care communication between End Users and Authorized Users; verifying eligibility, obtaining authorization, and submitting and adjudicating claims with payers and their agents; responding to safety events, alerts, or wellness checks; and personalizing the MyCompass experience (e.g., goal tracking, schedule configuration). This is the primary basis for most processing within the Services.
4.2 Authorization and Consent
Where an intended use or disclosure is not otherwise permitted by HIPAA, GMA relies on a signed HIPAA Authorization (45 CFR § 164.508) or other legal documentation provided by the End User (if legally competent) or the End User’s Legally Authorized Representative. These authorizations are logged in accordance with federal retention requirements.
4.3 Required by Law and Contractual Obligations
GMA may process data as required under federal, state, or local law, including compliance with Medicaid waiver programs, TRICARE and other government health programs, aging services, or state disability-service contracts; documentation of remote support service delivery; incident or audit reporting; and retention requirements mandated by funding agencies.
4.4 Uses Permitted by HIPAA for Health and Safety
As permitted under HIPAA (including 45 CFR § 164.512), GMA may use and disclose PHI to address serious threats to health or safety — for example, sending system alerts to authorized parties in the event of a fall, elopement, or inactivity; using app-based metadata to detect potential risks or failures; and managing emergency contact lists, device rules, or alert escalation. All such uses are governed by the minimum-necessary standard and user-role permissions.
4.5 Business Associate Agreements
Any vendor, contractor, or integrated service provider that processes or accesses PHI on behalf of GMA is subject to a Business Associate Agreement in compliance with 45 CFR § 164.502(e). These partners may use PHI/PII only to support service delivery and must maintain privacy and security controls at least as protective as GMA’s.
4.6 De-Identified and Aggregated Use
GMA may use de-identified data, stripped of identifiers under 45 CFR § 164.514, for quality assurance, product improvement, system analytics, and non-commercial research. No such use is traceable to any individual, and no marketing or advertising profiling is conducted with this data.
5. How We Use Information
GMA uses information solely to provide lawful, consented, and necessary services. All data handling is governed by the principles of privacy (access limited to authorized roles), security (data encrypted, access-controlled, and monitored), and confidentiality (minimum-necessary use). GMA does not sell, lease, or monetize user data, and does not use collected information for advertising or profiling.
5.1 Day-to-Day Remote Services (MyCompass App). To present schedules, reminders, and goal prompts; enable End Users to log progress and communicate needs; notify End Users of updates and achievements; tailor experiences to support plans; and help authorized personnel understand engagement or inactivity patterns. All interactions are encrypted and stored in HIPAA-compliant environments.
5.2 Secure Communication (Compass Care Calling App). To facilitate live interactions between End Users and their support network; track whether wellness or safety check-ins were attempted or completed; identify service gaps (e.g., repeated missed calls); log connection issues; and authenticate calling parties to protect against unauthorized access. No audio or video content is recorded or retained unless a future feature is explicitly enabled with legal authorization, user notice, and compliance with applicable recording-consent laws.
5.3 Alerts and Safety Events (Compass Care Alerts App). To notify Authorized Users of boundary exits, inactivity, potential falls, or system-status events; timestamp alert responses; maintain alert logs for quality assurance; assist with emergency communication under pre-authorized protocols; and identify false positives or optimize alert parameters. Location data is accessed only where explicitly enabled with appropriate consent; no continuous background tracking is performed.
5.4 Payment and Billing. To verify eligibility and benefits, obtain prior authorizations, document service delivery, and submit and reconcile claims with Medicaid, TRICARE, and other payers and their authorized agents, consistent with Sections 4.1 and 7.3.
5.5 System Integrity and Technical Support. To detect software bugs and crashes; maintain uptime, speed, and compatibility; track login activity and authorization to prevent unauthorized access; enforce MDM policies; and deliver technical support. No unrelated analytics, user profiling, or advertising frameworks are implemented.
5.6 Legal, Clinical, and Contractual Requirements. To satisfy required documentation for waiver-funded or publicly contracted services; reporting for incident management or support-plan outcomes; state or federal audit requests; and legally mandated disclosures (e.g., abuse, neglect, or imminent harm). All such uses are subject to the minimum-necessary standard, logged in audit trails, and reviewed by compliance staff.
5.7 Internal Quality Improvement and Risk Mitigation. Using de-identified or aggregated data, GMA may improve accessibility and usability, analyze response times and system health, develop training materials and internal controls, and proactively resolve safety risks or device issues. These uses do not involve identifiable user data unless permission is granted through a formal authorization process.
5.8 Strict No-Use Clauses. GMA does not use any data collected through the Services for behavioral advertising or marketing; sale or licensing to third parties; unconsented research; or personal profiling beyond necessary safety configurations.
6. Nora Caregiver Intelligence (Artificial Intelligence)
Nora Caregiver Intelligence (“Nora”) is an AI-enabled caregiver support feature available within the MyCompass App, the Compass Care apps, and the MyCompass Web Portal. This section describes how Nora processes information and the safeguards that apply.
6.1 Purpose and Function. Nora assists Authorized Users in delivering services by surfacing relevant context, organizing care information, and supporting caregiving tasks. Nora processes information, which may include PHI, solely for these caregiving-support purposes. Nora is a care-support feature and is not used for advertising, marketing, or profiling.
6.2 Infrastructure and Business Associate Coverage. Nora is operated by GMA on Amazon Web Services using AWS Bedrock, which is covered by GMA’s Business Associate Agreement with AWS. Model inference runs within GMA’s AWS environment. The underlying model provider does not receive GMA data as a separate party and does not retain GMA inputs or outputs to train its models.
6.3 No Training on PHI. PHI is never used to train any artificial-intelligence or machine-learning model. No model provider retains GMA data for training purposes.
6.4 Safeguards and Data Minimization. GMA applies layered safeguards to Nora, including encryption in transit and at rest, strict data minimization, role-based access, audit logging, and de-identification or tokenization of information where it does not impair the caregiving-support function. GMA limits the information made available to Nora to what is reasonably necessary for caregiving support.
6.5 Human Oversight. Nora provides decision support only. Nora does not make autonomous clinical, care, or safety determinations. Outputs from Nora that may affect an End User’s care or safety are reviewed by a qualified human before any action is taken. GMA maintains a human-in-the-loop approach for all care-affecting Nora functionality.
6.6 Accuracy and Limitations. AI-generated output may be incomplete or inaccurate and is intended to assist, not replace, the judgment of qualified caregivers and clinicians. Authorized Users remain responsible for care decisions.
6.7 Nondiscrimination. Consistent with Section 1557 of the Affordable Care Act and GMA’s nondiscrimination commitments, GMA evaluates Nora to guard against discriminatory outcomes based on race, color, national origin, sex, age, or disability, applies bias-mitigation and human-oversight controls, and does not use Nora to make or support decisions in a manner that unlawfully discriminates against End Users.
7. Disclosure of Information
GMA treats all personal and health-related information with the highest degree of confidentiality. GMA does not sell, lease, or monetize user data, and does not permit any third party to use the data for the third party’s own purposes. GMA discloses information only to deliver services, comply with the law, protect the safety of End Users, or fulfill authorized care agreements — and, when it does, only the minimum necessary information, to vetted recipients, under appropriate agreements.
7.1 Disclosures With Authorization
GMA will disclose PHI or PII to a third party when the End User has provided a HIPAA-compliant written authorization; the End User’s Legally Authorized Representative has authorized disclosure within the scope of their authority; or a contractual party (e.g., a Medicaid or other government-program provider or case manager) has legal standing under a state or federal program. Such disclosures may include information necessary for coordination of care, emergency contacts, or authorized clinical teams.
7.2 Disclosures Without Authorization (As Permitted by Law)
Under 45 CFR § 164.512, GMA may disclose information without authorization in limited, legally permissible situations: to avert a serious threat to health or safety; to public-health or social-services authorities as part of mandated reporting; to comply with a court order, subpoena, or legal investigation; to regulatory agencies conducting audits or licensing; to law enforcement under narrowly defined conditions (e.g., locating a missing vulnerable adult); to a medical examiner or coroner if required by law; and to government authorities where necessary to comply with national-security or protective-services laws. Such disclosures are tightly scoped to the minimum data required and documented under HIPAA’s accounting-of-disclosures rules (see Section 9.6).
7.3 Disclosures to Payers for Payment
GMA discloses PHI and Payment and Billing Information to government and commercial payers (including Medicaid, TRICARE, and other programs), their administrators, and clearinghouses, as necessary to verify eligibility, obtain authorization, and submit, document, and adjudicate claims for the Services. Payers act as independent covered entities or government agencies subject to their own legal obligations and are not GMA’s Business Associates when they receive information for their own payment, audit, or program-administration purposes.
7.4 Disclosures to Business Associates
GMA may share limited PHI or PII with Business Associates who perform services on GMA’s behalf, such as cloud storage, AI infrastructure (AWS Bedrock for Nora), notification infrastructure, MDM platforms, billing and revenue-cycle services, clearinghouses, and customer-support tools. All such entities are bound by a Business Associate Agreement under 45 CFR § 164.502(e) requiring them to use the information only for authorized services, protect it with industry-standard safeguards, and report any breach or unauthorized use immediately.
7.5 Internal Access Controls
Only GMA personnel with a legitimate “need to know” may access user data — e.g., support staff, administrators managing configurations, authorized clinicians or coordinators, and compliance or legal staff. Every access event is logged and monitored using secure audit controls.
7.6 Guardian and Authorized User Disclosures
Authorized Users may receive information only about End Users for whom they have documented legal or clinical authority, only within the scope of that authority, and only consistent with the limits of their access (e.g., read-only vs. full interaction). GMA honors court-ordered or statutory limits on a representative’s access, and End Users retain privacy rights where applicable law provides. No Authorized User may access PHI or system information outside their assigned role or permission scope. Misuse may result in immediate access suspension and legal action.
7.7 De-Identified and Aggregated Disclosures
GMA may share de-identified or aggregated information for quality improvement, research (only if not involving PHI), grant reporting, and public-health or education initiatives. Such information is scrubbed of all 18 HIPAA-defined identifiers and validated using the Safe Harbor or Expert Determination method.
7.8 No Sale and No Third-Party Monetization
GMA does not sell, rent, trade, or otherwise monetize your information — including PHI and any de-identified data derived from it — does not share it with advertisers or data brokers, and does not use it for advertising or marketing. GMA does not authorize any third party to use your information for the third party’s own purposes. This commitment is stated as Our Promise at the front of this Policy and is binding on GMA.
7.9 Business Transfers and Successor Obligations
GMA does not treat your information as a commercial asset to be sold. In the event of a merger, acquisition, investment, reorganization, bankruptcy, or sale or transfer of all or part of GMA’s business or assets, any PHI or other personal information will continue to be protected in accordance with this Policy and applicable law, and GMA will require any successor or acquirer to assume these obligations, including Our Promise, in writing. GMA will provide notice as required by law before any such information becomes subject to a materially different privacy practice and, where required, will offer the opportunity to consent or object.
8. Data Security and Retention
GMA implements rigorous administrative, physical, and technical safeguards designed to meet or exceed the standards of HIPAA, the HITECH Act, applicable state privacy and cybersecurity statutes, and industry best practices for mobile health and assistive technologies.
8.1 Data Encryption
All information is encrypted in transit using TLS 1.2 or higher, at rest using AES-256, and on devices under MDM controls where applicable. Encryption applies to personal identifiers and PHI across app and portal interactions, cloud storage, alert payloads, AI processing, and administrative tools.
8.2 Access Controls
Access is strictly role-based and limited to individuals with verified credentials and a documented need-to-know. GMA enforces multi-factor authentication for administrative and backend users, device-level security policies for managed devices, time-based session expiration and automatic logout, and audit logging of every login and data-access event.
8.3 Breach Detection and Notification
In accordance with HIPAA’s Breach Notification Rule (45 CFR §§ 164.400–414), GMA maintains a formal breach-response policy. In the event of a breach of unsecured PHI, GMA will investigate and contain the incident promptly; notify affected individuals (and their Legally Authorized Representatives, as appropriate) in writing without unreasonable delay and no later than 60 calendar days after discovery, unless an exception applies; notify the U.S. Department of Health and Human Services (HHS) and any relevant state agencies as required by law; and document the incident and take corrective action. All Business Associates and vendors must agree in writing to report suspected breaches immediately.
8.4 Data Retention
GMA retains PHI and PII for a minimum of seven (7) years from the date of last use, or longer as required by federal or state Medicaid, TRICARE, or other program documentation rules, managed-care contract provisions, waiver-program recordkeeping laws, or legal holds. Where retention timelines conflict, the longer duration applies. Records for minors may be retained for longer periods as required by applicable state law (e.g., until the age of majority plus a statutory period). Once retention obligations expire, data is securely destroyed or permanently de-identified using NIST 800-88–compliant methods. [Confirm with counsel and insert the precise Missouri, Medicaid, and TRICARE retention periods, including minor-record rules, before publication.]
8.5 Mobile Device Management and Monitoring
For GMA-issued or MDM-controlled devices, additional security and support features may apply: remote lock and wipe; prohibition of unauthorized applications; location features (only if explicitly authorized and enabled); usage-restriction and content-filtering policies; and regular device-health scans and update enforcement. No MDM software is installed without the consent of the End User or their Legally Authorized Representative, and MDM data is not used for advertising or non-service analytics.
GMA distinguishes safety-supportive monitoring from control of the End User. Any monitoring, filtering, or location feature is tied to a documented need in the End User’s support plan, configured to the least-intrusive setting that meets that need, reviewed periodically, and — where the End User has the capacity to participate — configured with the End User’s input. GMA discloses to the End User and their Legally Authorized Representative what is and is not monitored on a managed device.
8.6 Infrastructure and Hosting
All data is stored in secure, HIPAA-compliant cloud environments hosted in the United States. GMA’s infrastructure includes redundant backups, intrusion-detection systems, role-based administrative dashboards with least-privilege design, periodic penetration testing and vulnerability scans, and 24/7 uptime monitoring. The same safeguards extend to any on-premises home-support hardware that is part of the MyCompass System.
8.7 User Responsibility
All users are expected to keep login credentials confidential; immediately report lost or stolen devices; refrain from sharing app/portal screenshots or personal data externally; and use only authorized devices and app stores. GMA provides training and support for safe usage.
9. Your Rights and Choices
GMA respects the rights of all users to control their personal information and protected health data under HIPAA, the HITECH Act, and applicable state privacy and disability-service laws. The following rights apply subject to legal authority and verification of identity. A right held by an End User may be exercised by the End User’s Legally Authorized Representative within the scope of their authority.
9.1 Right to Access
You may request access to PII or PHI collected or stored through the Services, including service or support-plan records, logged activities or goals, alert and call history (if applicable), and device metadata. Requests may be made in writing to privacy@graymattersalliance.com. GMA will respond within 30 calendar days, with one 30-day extension where permitted under 45 CFR § 164.524, and may require verification of identity or authority.
9.2 Right to Correct or Amend Information
You may request corrections to inaccurate, incomplete, or outdated information, including personal identifiers, assigned caregivers or emergency contacts, support goals or communication preferences, and technical records with verifiable errors. Requests must be in writing; GMA will respond within the timelines required by HIPAA (45 CFR § 164.526) — generally within 60 calendar days, with one 30-day extension where permitted — and where feasible will respond sooner. Certain clinical records may require documented justification for amendment, and GMA may deny an amendment in the limited circumstances HIPAA permits, with a written explanation and your right to submit a statement of disagreement.
9.3 Right to Revoke Consent or Authorization
An End User or their Legally Authorized Representative may revoke a previously granted HIPAA Authorization or consent at any time, in writing. Upon revocation, GMA will discontinue future uses or disclosures based on that Authorization; the revocation will not apply retroactively to uses or disclosures already made; and certain ongoing services may be limited or suspended if revocation prevents essential care coordination. GMA will not retaliate against any person for exercising a privacy right, and where a revocation results in a change to or end of services, GMA will support a safe transition, including the timely transfer of records as authorized. A representative revoking app access for an Authorized User must submit a written request with legal documentation of authority.
9.4 Right to Request Restrictions
You may request restrictions on how GMA uses or discloses your PHI. While GMA is not required to agree to every requested restriction, it will review each request individually, honor any restriction it agrees to in writing (unless required by law to override it), and provide a written response with its decision and, if denied, a justification. As required by 45 CFR § 164.522(a)(1)(vi), GMA will honor a request to restrict disclosure of PHI to a health plan for payment or health-care-operations purposes where the item or service involved has been paid for in full, out of pocket, by you or on your behalf, except where the disclosure is otherwise required by law.
9.5 Right to a Copy in an Electronic Format
Consistent with HIPAA’s right of access (45 CFR § 164.524), upon request GMA will provide a copy of your PHI in a readable electronic format and, where readily producible, deliver it to you or to a third party you designate in writing. Any fee charged will be limited to a reasonable, cost-based fee as permitted by 45 CFR § 164.524(c)(4). Only data collected by GMA directly is included; data obtained from third-party services is excluded unless legally transferable.
9.6 Right to an Accounting of Disclosures
Consistent with 45 CFR § 164.528, you may request an accounting of certain disclosures of your PHI made by GMA. The accounting does not include disclosures for treatment, payment, or health care operations; disclosures made to you or pursuant to your authorization; and other categories excluded by law. Requests may be made in writing to the Privacy Officer (Section 16).
9.7 Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with GMA’s HIPAA Privacy Officer or with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). GMA prohibits retaliation against anyone who exercises this right.
9.8 Right to Deletion (Limited by HIPAA Retention Rules)
Medical or service-related data must be retained for the periods described in Section 8.4 and cannot be deleted on request during that period. However, non-clinical or auxiliary records (e.g., app notes, preferences) may be deleted on request; Authorized User accounts may be deleted when the user is no longer responsible for the End User; and full account deletion may occur after services terminate and records are no longer required for legal, billing, or compliance purposes. GMA will communicate the deletion timeline and any legal exceptions in its response.
9.9 Request Procedures
To make a request related to any of the rights above, contact GMA’s HIPAA Privacy Officer (Section 16). All requests will be acknowledged within 10 business days and completed within the timelines required by applicable law.
10. Accessibility, Effective Communication, and Language Access
GMA is committed to ensuring that this Policy and the consents and notices that accompany the Services are understandable and accessible to the people they serve, consistent with Section 1557 of the Affordable Care Act, the Americans with Disabilities Act, and Section 504 of the Rehabilitation Act.
-
Plain-language and accessible formats. GMA provides this Policy and key consent materials in plain language and, on request and at no cost, in accessible formats (such as large print, screen-reader-compatible electronic formats, or other auxiliary aids and services) to support effective communication with individuals with disabilities.
-
Language access. GMA provides language-assistance services, including translation or interpretation, to individuals with limited English proficiency, on request and at no cost, where required by applicable law.
-
How to request. To request this Policy or related materials in an accessible format or another language, contact the Privacy Officer (Section 16).
11. Third-Party Services, Integrations, and Connected Platforms
GMA uses select third-party service providers and connected platforms to operate the Services securely. These providers and platforms do not own, sell, or independently exploit your data. Except for Apple HealthKit/HomeKit (governed by Apple’s platform requirements described below), all third-party relationships involving PHI are governed by Business Associate Agreements, and no third party may use PHI or PII outside the scope of its engagement with GMA.
11.1 Categories of Third-Party Services
-
Cloud Hosting: encrypted, HIPAA-compliant U.S.-based environments (e.g., AWS).
-
AI Infrastructure: AWS Bedrock, used to operate Nora Caregiver Intelligence under BAA (see Section 6).
-
Mobile/Web App Infrastructure: push notifications, device updates, app distribution, and crash diagnostics, configured for HIPAA safety.
-
Secure Communication Tools: voice, video, or alert-based communication between End Users and Authorized Users (e.g., Agora).
-
Mobile Device Management: to configure, monitor, and secure GMA-issued devices.
-
Billing, Revenue-Cycle, and Clearinghouse Services: to verify eligibility, submit and adjudicate claims, and support payment operations under BAA.
-
Customer Support Systems: for support-ticket tracking and secure correspondence.
-
IoT and Hardware Integrations: approved devices such as medication dispensers, fall sensors, and environmental sensors, exchanging data through secure APIs under the same HIPAA standards as in-app data.
11.2 Apple HealthKit and HomeKit
Where enabled and authorized, the MyCompass System integrates with Apple HealthKit (health and fitness data) and Apple HomeKit (connected home/accessory data). Consistent with Apple’s requirements, GMA: uses HealthKit and HomeKit data solely to provide health, care, and safety functionality; does not use HealthKit or HomeKit data for advertising, marketing, data-mining, or sale; does not disclose HealthKit or HomeKit data to third parties except as needed to provide a health or service purpose with the user’s consent; and does not use this data for any purpose unrelated to the Services. Apple does not act as GMA’s Business Associate for HealthKit/HomeKit; once HealthKit/HomeKit data is received into the MyCompass System, GMA protects it as PHI under this Policy and the safeguards in Section 8.
11.3 Restrictions on Third Parties
All third-party service providers are prohibited from selling, reusing, or disclosing user data; using app data for marketing, advertising, analytics, or profiling; retaining data beyond what is required for contractual compliance; accessing audio, video, or location data unless technically necessary and contractually permitted; and subcontracting without GMA’s written consent and a downstream HIPAA-compliant agreement.
11.4 IoT Vendor Diligence and BAA Requirement
Before integrating any IoT device or platform that may transmit PHI, GMA requires a signed Business Associate Agreement or comparable HIPAA-compliant data-protection contract. Where a device or vendor cannot or will not enter a BAA, GMA will either de-identify data before transmission, limit the integration so that no PHI is exchanged, or decline the integration. GMA does not expose identifiable client data to vendors that have not contractually agreed to HIPAA-level protections.
11.5 Guardian and Client Awareness
When a third-party tool or device is involved in delivering care, GMA will identify the tool in onboarding materials or device guides, provide instructions regarding configuration and consent, offer training or support for approved integrations, and ensure data remains within the boundaries of authorized use.
11.6 Public App Store Requirements
To comply with Apple App Store and Google Play policies, any third-party SDKs or APIs embedded in the apps are configured to disable advertising-tracking features, analytics not required for security or bug resolution, and device fingerprinting or app-based profiling. GMA does not share Apple or Android device identifiers (e.g., IDFA, AAID) with third parties for commercial purposes.
12. Children’s and Incapacitated Adults’ Privacy
The Services may be used by or on behalf of individuals who are minors, incapacitated adults, or individuals under guardianship or supported-decision-making agreements. GMA takes extra precautions to ensure all such data is handled in compliance with HIPAA, applicable state laws regarding minors and guardianship, and best practices for vulnerable populations.
12.1 Age Restrictions and Guardian Access
An End User may use the MyCompass App regardless of age, provided the individual is a recipient of GMA services and the app is configured appropriately. For End Users under 18, or those declared legally incapacitated or requiring substituted or supported decision-making, a Legally Authorized Representative must act on their behalf for authorization of data access, consent to terms, configuration of app settings, and activation of safety or communication features. GMA requires documentation of legal authority (e.g., guardianship orders, power of attorney, supported-decision-making agreement) before enabling access by an Authorized User acting on behalf of another person, and limits that access to the scope of the documented authority.
12.2 Collection of Information from Minors
GMA obtains verifiable guardian or parental consent before collecting PHI or PII from a minor, and does not knowingly collect such information from minors without it. Where services are provided to a person under 18, or an adult lacking legal capacity, data collection is limited to the minimum necessary and directed solely to support care delivery under the authorization of a Legally Authorized Representative. GMA does not engage in behavioral tracking, targeted advertising, or profiling of minors.
12.3 Role of Guardians and Authorized Representatives
Within the scope of their documented legal authority, Legally Authorized Representatives may set up and manage user profiles, determine who may access the Compass Care Calling or Alerts apps, enable or restrict alert thresholds and notifications, and revoke access or request updates on behalf of the End User. GMA honors court-ordered or statutory limits on a representative’s access. All representative activities are logged and stored in accordance with HIPAA audit requirements.
12.4 Supported Decision-Making and Retained Rights
GMA presumes that an End User has capacity except to the extent a court order or applicable law provides otherwise, and supports supported-decision-making arrangements. For End Users with partial capacity who require assistance, GMA configures the Services to default toward End-User participation where possible — including shared access, tailored interface configurations, and prompting mechanisms that allow participation with guidance. GMA recognizes that capacity is contextual and may change over time; changes to a person’s access following a change in capacity require appropriate documentation. End Users retain the privacy rights afforded to them under applicable law, including as against a representative where the law or a court order so provides.
12.5 Heightened Protection of Sensitive Status
GMA recognizes that an individual’s status as an End User, and related data, may reveal disability or health conditions that are highly sensitive. GMA treats this information with heightened protection, limits access to those with a need to know, and does not use it to discriminate against or otherwise disadvantage an End User.
12.6 COPPA Compliance
GMA’s apps are not directed to the general public or to children under 13 for independent use. In any case where a child under 13 may use an app, verifiable guardian consent and oversight are required, and all collection is solely for service delivery and protection, consistent with the Children’s Online Privacy Protection Act (COPPA).
13. Information Not Governed by HIPAA; State Privacy Rights
13.1 Information Not Governed by HIPAA
Most information processed through the Services is PHI governed by HIPAA. Some information — for example, analytics from GMA’s public website, account information created before any health context exists, or certain device diagnostics — may fall outside HIPAA. GMA handles that information consistent with this Policy and applicable consumer-privacy law: GMA does not sell it, does not use it for cross-context behavioral advertising, and applies reasonable security safeguards to it.
13.2 State Privacy Rights
Depending on where you live, state law may give you additional rights with respect to personal data or consumer health data that is not otherwise exempt as PHI or covered-entity data — for example, under the Washington My Health My Data Act, Nevada’s consumer-health-data law, and comprehensive privacy laws in states such as California, Virginia, Colorado, and Connecticut. These rights may include the right to access, correct, delete, or obtain a copy of certain personal data, and to opt out of certain processing. Many of these laws exempt PHI and information handled by HIPAA-covered entities; where an exemption applies, that information continues to be governed by HIPAA and this Policy. To exercise any state-law right that applies to you, contact the Privacy Officer (Section 16); GMA will respond as required by the applicable law and will not discriminate against you for exercising a right.
14. Governing Law and Relationship to Other Agreements
This Policy is governed by the laws of the State of Missouri and applicable U.S. federal law, without regard to conflict-of-laws principles, except where the law of another state mandatorily applies to a particular individual or category of data. The Services are intended for use in the United States, and information is processed and stored in the United States.
This Policy addresses privacy practices. It is part of, and is supplemented by, GMA’s End User License Agreement and any applicable Terms of Use or service agreement, which govern matters such as permitted use, limitations of liability, warranties, and dispute resolution. Where this Policy and the NPP address the same HIPAA subject, the NPP governs GMA’s formal HIPAA obligations (see Section 1.2). Nothing in any agreement purports to waive rights that cannot be waived under applicable law, including the privacy rights of End Users.
15. Other Applicable Laws
GMA complies with other federal and state laws that may apply to particular services or data. For example, where any service is delivered in an educational setting subject to the Family Educational Rights and Privacy Act (FERPA), where any records are subject to the federal confidentiality rules for substance-use-disorder treatment records (42 CFR Part 2), or where genetic information is involved under the Genetic Information Nondiscrimination Act (GINA), GMA handles that information in accordance with those laws in addition to this Policy. Where any such law imposes stricter requirements than this Policy, the stricter requirement applies.
16. Contact Information
GMA has designated a HIPAA Privacy Officer to oversee privacy-related matters, ensure compliance with federal and state data-protection laws, respond to inquiries, and handle concerns regarding the handling of personal or health information across the Services.
HIPAA Privacy Officer
Name: Kyle Dortch
Title: Chief Administrative Officer & HIPAA Privacy Officer
Organization: Gray Matters Alliance, LLC
Privacy & rights requests: privacy@graymattersalliance.com
Privacy Officer (escalation): kyle@graymattersalliance.com
Phone: 314-266-2678
Mailing Address: Gray Matters Alliance, 119 S Main Street, St. Charles, MO 63301, United States
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with Gray Matters Alliance (using the contact information above) or with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR).
-
OCR Website: https://www.hhs.gov/hipaa/filing-a-complaint/
-
OCR Phone: 1-800-368-1019
You will not be retaliated against for filing a complaint.
Response Timeframes. GMA will acknowledge all privacy-related inquiries within 10 business days and respond in full within the timelines required by HIPAA, state law, or relevant service agreements (generally within 30 calendar days for access requests and within the period described in Section 9.2 for amendment requests).
17. Changes to This Privacy Policy
GMA may update or modify this Policy at any time to reflect changes in applicable laws (including HIPAA, HITECH, or state rules); updates to the functionality, features, or integrations of the Services; enhancements to security or data-handling practices; or operational changes affecting how information is managed.
Any changes will be posted prominently within the apps and Web Portal, published on the official GMA website, and communicated directly to Authorized Users and End Users (or their Legally Authorized Representatives) when legally required or where changes involve material alterations to data use or user rights.
17.1 Effective Date of Revisions. Each updated version will include a clearly stated “Last Updated” date and version number at the top. Users are encouraged to review the Policy periodically.
17.2 Continued Use as Acceptance. By continuing to use the Services after an updated Policy is posted, you (or the Legally Authorized Representative who accepts on an End User’s behalf under Section 1.3) acknowledge and accept the revised terms. If you disagree with any material changes, you may discontinue use and request assistance with account closure.
17.3 Notification for Material Changes. For material changes (e.g., expanded use of PHI, new categories of data collected, or changes in legal rights), GMA will provide advance notice via in-app messaging or email to affected users; offer an opportunity to re-consent where required; and retain a historical record of prior versions.
Privacy Snapshot (for App Store & Google Play)
Developer: Gray Matters Alliance, LLC (GMA)
Apps covered:
-
MyCompass (iOS only — End Users)
-
Compass Care Calling (iOS & Android — Authorized Users)
-
Compass Care Alerts (iOS & Android — Authorized Users)
Category: Medical / Health & Fitness
Region & Hosting: Data processed and stored in the United States (HIPAA-compliant).
Regulatory posture: HIPAA/HITECH compliant. The Services are not a medical device and not a personal emergency response system (PERS); they are part of GMA’s custom remote-support solution and are not a substitute for 911 or emergency services.
AI: Includes Nora Caregiver Intelligence, operated on AWS Bedrock under BAA, with human oversight and no use of PHI to train models.
Contact: privacy@graymattersalliance.com · 314-266-2678
Full Privacy Policy URL: https://www.graymattersalliance.com/privacy
We do not:
-
Sell, rent, or trade your information — including de-identified data — ever; use behavioral ads; or share data with advertisers or data brokers.
-
Transfer your information in a business deal without binding any successor to this same promise.
-
Track you across apps or websites owned by other companies.
-
Use HealthKit, HomeKit, or any care data for advertising, marketing, or data-mining.
-
Use PHI to train AI models.
We do:
-
Collect only what’s necessary for care, safety, and app functionality.
-
Encrypt data in transit (TLS) and at rest (AES-256).
-
Restrict access by role/authorization; all access is logged.
-
Use Business Associates under HIPAA; no third-party monetization.
-
Operate Nora Caregiver Intelligence on AWS Bedrock under BAA with human oversight.
-
Honor user/representative rights (access, correction, restrictions, revocation, accounting), with medical-record retention of at least 7 years.
-
Provide this notice in accessible formats and other languages on request.
Apple “App Privacy” Summary (App Store Connect)
Data Used to Track You: None.
Data Linked to You (for app functionality, account management, safety, customer support, security/compliance):
-
Contact Info: name, email/phone (all apps)
-
Identifiers: account ID, device token, IP/device info (all apps)
-
Health & Fitness / Health Data (PHI): only where applicable to care, including Apple HealthKit data where enabled (MyCompass; limited alert context in Alerts)
-
Home Data (Apple HomeKit): only where enabled, to support safety and care functionality
-
Usage Data: app interactions, timestamps, login events (all apps)
-
Location (approximate): Alerts only, and only if enabled by the End User’s Legally Authorized Representative
Data Not Linked to You:
-
Diagnostics: crash logs, performance data (all apps)
We do not collect precise location, contacts, photos, microphone, or camera content unless a future feature explicitly requests it with clear in-app consent. HealthKit and HomeKit data are used solely for health, care, and safety purposes and are never used for advertising, marketing, data-mining, or sale.
Google Play “Data Safety” (Calling & Alerts)
-
Data collected: Contact info, identifiers, usage data, diagnostics; Alerts may collect approximate location if enabled.
-
Data shared: No data shared for advertising. GMA does not sell user data. Sharing is limited to HIPAA Business Associates for app operations.
-
Security: Encrypted in transit and at rest; access is role-based and audited.
-
Data deletion: Users/representatives may request account/data actions; medical records retained ≥ 7 years as required.
-
AI: Nora Caregiver Intelligence runs on AWS Bedrock under BAA; PHI is not used to train models.
-
Purpose of collection: App functionality, safety notifications, communications, security/compliance, customer support, diagnostics.
-
Optional location: Alerts only, with explicit configuration by the End User’s Legally Authorized Representative.
Per-App Snapshots
1) MyCompass (iOS — End Users)
-
Collects (Linked to You): Contact Info, Identifiers, Health/Service data (goals, schedules, support notes), Usage Data; Apple HealthKit data where enabled.
-
Diagnostics (Not Linked): crash/performance logs.
-
Location: Not collected.
-
AI: Nora Caregiver Intelligence available, with human oversight; no PHI used for model training.
-
Used for: app functionality, care coordination, safety reminders, account management, security/compliance, support.
-
Does not: record audio/video, use advertising IDs, or profile for marketing.
-
Typical Permissions: Notifications; Internet; HealthKit/HomeKit (only if enabled). No camera/mic/location required as currently designed.
2) Compass Care Calling (iOS & Android — Authorized Users)
-
Collects (Linked to You): Contact Info, Identifiers, Usage Data, Call metadata (timestamps, duration, direction).
-
Diagnostics (Not Linked): crash/performance logs.
-
Location: Not collected.
-
Used for: secure communication, verification/authentication, reliability/diagnostics, security/compliance.
-
Does not: record or store call audio/video content.
-
Typical Permissions: Notifications; Network; (Android) “Phone” for calls over data; foreground service for connectivity.
3) Compass Care Alerts (iOS & Android — Authorized Users)
-
Collects (Linked to You): Contact Info, Identifiers, Usage Data, Alert metadata (type, time, status, recipient), Optional approximate location (only if enabled by the Legally Authorized Representative).
-
Diagnostics (Not Linked): crash/performance logs.
-
Used for: safety notifications, emergency workflows, audit trails, security/compliance.
-
Location: Optional & event-based (no continuous background tracking unless explicitly configured).
-
Typical Permissions: Notifications; (Optional) Location “When In Use” for alert workflows; foreground service on Android for timely alerts.
User Rights & Support (all apps)
-
Access / Corrections / Restrictions / Revocation / Accounting: Contact GMA’s HIPAA Privacy Officer (Section 16) or the privacy intake address.
-
Deletion: Available where legally permissible; clinical/service records retained ≥ 7 years per law.
-
Accessibility & language: This notice is available in accessible formats and other languages on request.
-
Complaints: Contact GMA’s Privacy Officer or HHS-OCR (no retaliation).
Notice of Privacy Practices
Gray Matters Alliance, LLC
NOTICE OF PRIVACY PRACTICES
Effective Date: July 6, 2026
​
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
​
Who This Notice Covers
​
This Notice of Privacy Practices (“Notice”) describes how Gray Matters Alliance, LLC (“GMA,” “we,” “us,” or “our”) may use and disclose your protected health information (“PHI”) and how you can access that information. “PHI” is information about you, including demographic information, that may identify you and that relates to your past, present, or future physical or mental health or condition, the provision of services to you, or payment for those services.
This Notice applies to GMA and its entire workforce and covers PHI created or received in connection with the services and technology GMA provides, including the MyCompass™ App, the Compass Care Calling™ App, the Compass Care Alerts™ App, the MyCompass™ Web Portal, Nora Caregiver Intelligence™, and the connected components of the MyCompass System™ (collectively, the “Services”). GMA is a Covered Entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (together, “HIPAA”).
This Notice works together with GMA’s Mobile App & Platform Privacy Policy. Where that Privacy Policy and this Notice address the same subject, this Notice governs GMA’s formal HIPAA obligations.
​
Our Legal Duties
​
GMA is required by law to:
-
Maintain the privacy and security of your PHI;
-
Provide you with this Notice of our legal duties and privacy practices with respect to your PHI;
-
Follow the terms of the Notice that is currently in effect;
-
Notify you following a breach of unsecured PHI, as required by law; and
-
Obtain your written authorization for uses and disclosures not described in this Notice, and honor your right to revoke that authorization.
We will not use or disclose your PHI without your written authorization except as described in this Notice or as otherwise permitted or required by law.
​
How We May Use and Disclose Your PHI Without Your Authorization
​
The following categories describe the ways we may use and disclose your PHI. For each category we explain what we mean and give an example. Not every use or disclosure in a category is listed, but all permitted uses and disclosures fall within one of these categories.
​
For Treatment
We may use and disclose your PHI to provide, coordinate, and manage your remote support services and care. We may share PHI with the members of your support team — including guardians, clinicians, care coordinators, and authorized caregivers — so they can carry out your support plan. Example: We may disclose your goals, schedule, or a safety alert (such as a fall or elopement notification) to an authorized caregiver so they can respond to your needs.
​
For Payment
​
We may use and disclose your PHI to obtain payment for the services we provide. This includes verifying your eligibility and benefits, obtaining prior authorizations, documenting the medical necessity of services, submitting and adjudicating claims, coordinating benefits among payers, and responding to audits or recoupment reviews. We may disclose PHI to government and commercial payers — including Medicaid, TRICARE, and other government health programs — their contractors and administrators, and to clearinghouses and billing vendors that act as our Business Associates.
Example: We may send a claim containing your diagnosis, the services delivered, and supporting documentation to Medicaid, a Medicaid managed-care organization, or Humana Government Business (for TRICARE) so that we can be paid for your services.
​
For Health Care Operations
​
We may use and disclose your PHI to run our organization and make sure you receive quality services. This includes quality assessment and improvement, training and evaluating our workforce, care coordination, compliance and audit activities, and general administration.
Example: We may review service records to evaluate how well our alerting features perform and to improve the safety and accessibility of the MyCompass System.
​
To Business Associates
​
We may disclose PHI to third parties that perform functions on our behalf — such as cloud hosting, communication and notification services, mobile device management, AI infrastructure (AWS Bedrock, which supports Nora Caregiver Intelligence), billing and revenue-cycle services, and clearinghouses. Each Business Associate is bound by a written agreement requiring it to protect your PHI and to use it only for the services it performs for us.
​
To Persons Involved in Your Care
​
Unless you object, we may share PHI with a family member, guardian, personal representative, or other person you identify who is involved in your care or payment for your care, to the extent relevant to that involvement. We may also share PHI to notify such a person of your location or general condition in an emergency.
​
Reminders and Care-Related Communications
​
We may contact you or your representative with service reminders, schedule prompts, wellness check-ins, or information about treatment alternatives or other health-related benefits and services that may be of interest to you. These communications are part of your care and are not marketing.
​
Other Uses and Disclosures Permitted or Required by Law
​
We may use or disclose your PHI without your authorization in the following circumstances, subject to the conditions and limitations the law requires:
-
As Required by Law: when federal, state, or local law requires the use or disclosure.
-
Public Health Activities: to public-health authorities for activities such as preventing disease, reporting reactions to medications, or reporting certain events.
-
Victims of Abuse, Neglect, or Exploitation: to appropriate government authorities, including adult protective services, if we reasonably believe a person is a victim of abuse, neglect, or exploitation, consistent with mandatory-reporting laws that protect vulnerable adults and children.
-
Health Oversight Activities: to oversight agencies for audits, investigations, licensure, and other activities authorized by law, including Medicaid and other program-integrity reviews.
-
Judicial and Administrative Proceedings: in response to a court or administrative order, or a subpoena or discovery request where the required assurances are provided.
-
Law Enforcement: for limited law-enforcement purposes permitted by law, such as helping to locate a missing vulnerable adult or responding to valid legal process.
-
Coroners, Medical Examiners, and Funeral Directors: as necessary for them to carry out their duties.
-
To Avert a Serious Threat to Health or Safety: to prevent or lessen a serious and imminent threat to the health or safety of a person or the public.
-
Specialized Government Functions: for military and veterans’ activities (for example, as required by appropriate military command authorities for Armed Forces personnel and TRICARE beneficiaries), national security and intelligence, and protective services.
-
Workers’ Compensation: as authorized by and to the extent necessary to comply with workers’-compensation laws.
-
Research: for research that has been approved through a process that protects your privacy, or with your authorization.
-
Others Permitted by Law: and other uses and disclosures permitted by 45 CFR § 164.512 under the conditions that section requires.
​
Uses and Disclosures That Require Your Written Authorization
​
The following uses and disclosures will be made only with your written authorization:
-
Psychotherapy notes, where we maintain them;
-
Marketing, as defined by HIPAA; and
-
Any sale of PHI.
Most other uses and disclosures not described in this Notice will also be made only with your written authorization. If you give us authorization, you may revoke it at any time, in writing, and we will stop the uses and disclosures it covers going forward. Revocation will not apply to uses or disclosures we already made in reliance on your authorization, and it will not apply where we are legally required to continue.
GMA does not sell your PHI and does not use your PHI for marketing, advertising, fundraising, or profiling. We do not use your information to train artificial-intelligence models.
​
Your Rights Regarding Your PHI
​
You have the following rights with respect to your PHI. To exercise any of these rights, contact our Privacy Officer using the information at the end of this Notice.
​
Right to Request Restrictions
​
You have the right to request that we restrict how we use or disclose your PHI for treatment, payment, or health care operations, or to persons involved in your care. We are not required to agree to every requested restriction, but if we do agree, we will honor it unless the information is needed to provide you emergency treatment or the law requires the disclosure.
Mandatory restriction (self-pay). We must agree to your request to restrict disclosure of PHI to a health plan if the disclosure is for payment or health care operations and the item or service involved has been paid for in full, out of pocket, by you or on your behalf — unless the disclosure is otherwise required by law.
​
Right to Confidential Communications
​
You have the right to ask that we communicate with you about your PHI by alternative means or at an alternative location — for example, by a particular phone number, email, or address. We will accommodate reasonable requests.
​
Right to Inspect and Copy
​
You have the right to inspect and obtain a copy of the PHI we maintain about you in a designated record set, including the right to receive a copy in a readable electronic format where we maintain it electronically, and to direct us to send a copy to a third party you designate in writing. We will respond within the time HIPAA requires (generally 30 days, with one 30-day extension where permitted). We may charge a reasonable, cost-based fee as allowed by law. In limited circumstances we may deny a request, and where the law provides, you may have the denial reviewed.
​
Right to Amend
​
If you believe PHI we maintain about you is incorrect or incomplete, you have the right to request that we amend it. We will respond within the time HIPAA requires (generally 60 days, with one 30-day extension where permitted). We may deny your request in certain cases; if we do, we will explain why in writing and you may submit a statement of disagreement.
​
Right to an Accounting of Disclosures
​
You have the right to request an accounting of certain disclosures of your PHI that we made. The accounting does not include disclosures for treatment, payment, or health care operations; disclosures made to you or with your authorization; and certain other disclosures excluded by law.
​
Right to a Paper Copy of This Notice
​
You have the right to a paper copy of this Notice at any time, even if you have agreed to receive it electronically. You may request a copy from our Privacy Officer.
​
Right to Be Notified of a Breach
​
You have the right to be notified if we (or one of our Business Associates) discover a breach of your unsecured PHI, as required by law.
​
Right to Choose Someone to Act for You
​
If you have a legal guardian, hold a valid power of attorney for health care, or have another personal representative authorized under law, that person may exercise your rights and make choices about your PHI, within the scope of their authority. We will require documentation of that authority, and we will honor court-ordered or statutory limits on a representative’s access.
​
Accessibility and Language Assistance
​
Consistent with Section 1557 of the Affordable Care Act, the Americans with Disabilities Act, and Section 504 of the Rehabilitation Act, we provide this Notice and related materials, on request and at no cost, in plain language, in accessible formats (such as large print or screen-reader-compatible electronic formats), and with language-assistance services for individuals with limited English proficiency.
MyCompass User Agreement
GRAY MATTERS ALLIANCE, LLC
MYCOMPASS SYSTEM USER AGREEMENT
​
Effective Date: August 15 2025 Version: 2.0 Last Updated: July 06 2026
THIS AGREEMENT CONTAINS IMPORTANT INFORMATION ABOUT YOUR RIGHTS AND OBLIGATIONS, INCLUDING CONDITIONS, LIMITATIONS, AND EXCLUSIONS THAT MAY APPLY TO YOU. PLEASE READ IT CAREFULLY. SECTION 21 REQUIRES THAT MOST DISPUTES BE RESOLVED BY BINDING ARBITRATION ON AN INDIVIDUAL BASIS RATHER THAN BY JURY TRIAL OR CLASS ACTION — AND SECTION 21(b) EXPLAINS HOW YOU MAY OPT OUT OF ARBITRATION WITHIN 30 DAYS. THIS AGREEMENT GOVERNS THE MYCOMPASS TECHNOLOGY PLATFORM AND THE SUPPORT SERVICES DESCRIBED IN SECTION 15. GMA'S SUPPORT SERVICES — INCLUDING CHECK-INS, SAFETY ASSESSMENTS, AND EQUIPMENT ASSISTANCE — ARE CONSULTATIVE SUGGESTIONS ONLY; THEY ARE NOT THERAPY, TREATMENT, CLINICAL EVALUATION, OR EMERGENCY RESPONSE.
​
1. INTRODUCTION; ACCEPTANCE
​
This User Agreement (the "Agreement" or "Contract") is a legally binding contract between you and Gray Matters Alliance, LLC, a Missouri limited liability company organized under Chapter 347 of the Revised Statutes of Missouri ("GMA," "we," or "us"). You accept this Agreement by signing it, clicking "I Agree," "Sign Up," or a similar button, or by registering for, accessing, or using the Services. If you do not agree, do not accept and do not access or use the Services. You may end this Agreement at any time as described in Section 20. The Privacy Policy, the Notice of Privacy Practices, and the Documentation are incorporated by reference into this Agreement and form part of the contract between you and GMA.
a. Accessible Acceptance. GMA will make acceptance of this Agreement available through accessible means, including augmentative and alternative communication (AAC) devices, eye-gaze and switch access, screen readers, large print, verbal assent witnessed and documented by GMA personnel, and acceptance by a Legally Authorized Representative under Section 2. Auxiliary aids, language assistance, and a paper copy of this Agreement are available free of charge on request.
b. Electronic Records Consent. By accepting electronically, you agree that this Agreement may be executed and delivered by electronic means under the Missouri Uniform Electronic Transactions Act (§§ 432.200–432.295, RSMo) and the federal E-SIGN Act, and you consent to receive this Agreement, related notices, and disclosures electronically. You may withdraw that consent or request paper copies at any time by contacting us at the address in Section 22(e); withdrawal does not terminate the Agreement but may limit features that depend on electronic delivery.
​
2. CAPACITY; LEGALLY AUTHORIZED REPRESENTATIVES; MINORS
​
a. Presumption of Capacity. Adults are presumed to have the capacity to accept this Agreement. GMA honors supported decision-making: an End User may receive assistance from persons of their choosing in reviewing and deciding whether to accept, and the use of such support does not diminish the End User's own acceptance.
b. Legally Authorized Representatives. If an End User lacks legal capacity to contract, this Agreement must be accepted on the End User's behalf by a Legally Authorized Representative ("LAR") — a guardian or conservator appointed under Chapter 475, RSMo, an attorney-in-fact acting under a valid durable power of attorney under the Missouri Durable Power of Attorney Law (§§ 404.700–404.735, RSMo), or a person holding equivalent authority under the law of the End User's state of residence — acting within the scope of that authority. Consistent with Missouri's least-restrictive-alternative principles (§ 475.075, RSMo), GMA will look to the least-restrictive valid authority sufficient for the decision at hand. The LAR represents that their authority is valid and current and agrees to provide documentation of it on GMA's request. Acceptance by an LAR binds the End User only to the extent permitted by law, and the End User retains all rights not lawfully delegated to the LAR.
c. Minors; Children Under 13. The Services may be used by an individual under 18 only if this Agreement is accepted by the minor's parent, guardian, or LAR, who agrees to be responsible for the minor's use. For End Users under 13, GMA complies with the Children's Online Privacy Protection Act (COPPA): GMA obtains verifiable parental consent before collecting personal information from the child; collects no more personal information than is reasonably necessary to provide the Services; and does not condition the child's use of the Services on the collection of more information than necessary. The consenting parent or guardian may at any time review the child's personal information, direct GMA to delete it, and refuse to permit further collection or use (which may require ending the child's Subscription). Children's information is handled as described in our Privacy Policy and, where it is PHI, under HIPAA and Section 11.
d. Parental Controls. At the request of a parent or guardian, GMA will configure content filtering, usage restrictions, and activity monitoring for a minor End User's device and Account, using GMA's mobile device management and filtering tools, consistent with the Privacy Policy. GMA will implement the configuration the parent or guardian directs within the capabilities of the Services; the parent or guardian remains responsible for supervising the minor's use, and no filtering or monitoring technology is guaranteed to block all content or detect all activity.
e. Caregivers and Contacts. If you are accepting as a Caregiver or contact, you are accepting for yourself, concerning your own use of the Services; you are not certifying the End User's capacity, and you are not assuming the End User's obligations.
​
3. THE SERVICES
​
This Agreement applies to GMA's technology platform and applications, currently comprising the MyCompass App, the Compass Care Calling App, the Compass Care Alerts App, the MyCompass Web Portal, Nora Caregiver Intelligence, and any legacy GMA platform versions (including GMA System II™ and GMA System III™) until retired (collectively, the "MyCompass System," the "Services," or the "Platform"). The Services provide assistive communication, remote support, care coordination, and related technology functions described in the Documentation, together with ongoing and monthly support from GMA's support team as described in Section 15. GMA does not provide clinical services; support services are consultative, as described in Section 15(b).
a. GMA-Provided Device. Unless your order form states otherwise, GMA provides the tablet or other device used to access the Services. The device remains GMA's property and is provided for the End User's use during the Subscription. You agree to take reasonable care of the device, to use it only with the Services, and to promptly report loss, theft, or damage. Normal wear is expected. GMA will replace the device — meaning the GMA-provided tablet or comparable hardware running the GMA System — one (1) time during the Subscription in the event of loss, damage, or malfunction; any additional replacements are handled as stated in your order form. This one-time replacement does not include IoT devices, sensors, or other Integrated Service hardware (for example, physiologic monitoring sensors, elopement-detection or incontinence-monitoring devices, wearables, or robotic feeding devices); those products are covered, if at all, by the applicable manufacturer's or vendor's warranty — including the warranties of GMA's business associate partners — and not by GMA. See Sections 13(c) and 15(c). Upon termination, GMA-provided devices are released to you as described in Section 20(f), not returned. GMA-provided devices are managed through GMA's mobile device management tools as described in the Privacy Policy (and, for minors, Section 2(d)).
b. GMA-Provided Connectivity. GMA provides cellular data connectivity for GMA-provided devices through national carrier partners under contract with GMA (currently including Verizon and T-Mobile), covered by Business Associate Agreements where PHI is transmitted. GMA will use commercially reasonable efforts to maintain connectivity through its carrier partners, but does not control carrier networks; see Section 8.
​
4. CHANGES TO THIS AGREEMENT
​
We may modify this Agreement and our Privacy Policy from time to time. Changes are not retroactive. If we make material changes, we will notify you through the Services or by other reasonable means before the changes take effect, with an opportunity to review them. Material changes to Section 21 (Dispute Resolution) or to our data practices will take effect for you only upon your affirmative acceptance, or upon clearly presented notice with a genuine opportunity to decline and close your Account with transition support under Section 20(e). For other changes, your continued use of the Services after the effective date constitutes acceptance. If you object to any change, you may close your Account and stop using the Services.
​
5. YOUR ACCOUNT
​
a. Credentials. Do not share your password or username. Notify us promptly at itsupport@graymattersalliance.com if you believe your Account or credentials have been compromised. You are responsible for activity occurring through your Account until you report misuse or close the Account.
b. Ownership of Account. As between you and others, your Account belongs to you. If your Subscription is funded by another party (for example, a Facility or a family member), the funding party may end its funding of your Subscription, and your access may terminate to the extent it was paid for by that party — subject to the notice, data-export, and transition protections in Section 20(e).
c. Suspension and Disablement. We may disable an Account immediately, for so long as reasonably necessary, to protect the Services or address a violation of this Agreement. If we do, we will promptly notify you, explain the basis where lawful to do so, and provide a process to seek review and reinstatement. To question a suspension, or to terminate or permanently delete your Account, contact itsupport@graymattersalliance.com or info@graymattersalliance.com.
​
6. USE; RESTRICTIONS
​
You may use the Services only during the Term, in accordance with this Agreement and the Documentation. You agree not to, and not to permit any third party to: (a) sublicense, redistribute, sell, lease, lend, or rent the Services; (b) make the Services available over a network for simultaneous use by multiple devices owned or operated by different people, except as the Services are designed to permit; (c) disassemble, reverse engineer, decompile, decrypt, or attempt to derive the source code of the Services; (d) copy, modify, or create derivative works of the Services; (e) circumvent or interfere with security or access-control features; (f) use the Services' communications systems to send unauthorized or unsolicited commercial communications; (g) attempt to gain unauthorized access to, test the vulnerability of, or disrupt the Services; (h) distribute spam or malware; or (i) use the Services in any way that violates the privacy or rights of others or any applicable law, or for any unlawful or harmful purpose.
​
7. THIRD-PARTY SOFTWARE AND SERVICES
​
a. Integrated Services. The Services interoperate with hardware, software, and services provided by third parties that GMA has selected and contracted with — for example, physiologic and safety sensors, medication reminder and dispensing tools, wearables, and communication services ("Integrated Services"). Before any Integrated Service exchanges Protected Health Information with the Platform, GMA requires a Business Associate Agreement or comparable HIPAA-compliant data-protection contract, as described in our Privacy Policy. GMA remains responsible for its contracted service providers to the extent required by law and those agreements.
b. Incidental Third-Party Software. Software provided by a third party and installed on your tablet or device as part of the Services may be used only in connection with the Services and is subject to that third party's license terms.
c. Apple HealthKit and HomeKit. Where enabled and authorized by you, the Platform integrates with Apple HealthKit and HomeKit. GMA uses that data solely to provide health, care, and safety functionality; does not use it for advertising, marketing, or sale; and protects it as PHI under our Privacy Policy once received into the MyCompass System.
d. Independent Third-Party Services and Links. The Services may also enable you to reach websites, content, or services that you obtain independently from third parties outside the MyCompass System ("Independent Services"), which are governed by their own terms. GMA does not control Independent Services and, to the maximum extent permitted by law, is not responsible for them; your interactions with Independent Services are between you and the third party. This subsection does not limit GMA's responsibility for Integrated Services under Section 7(a) or GMA's obligations under HIPAA and the Privacy Policy.
​
8. NETWORK LIMITATIONS
​
Where GMA provides your device and cellular connectivity (Section 3(a)-(b)), GMA will use commercially reasonable efforts to maintain service through its carrier partners; where you use your own device or network, access depends on your device's capabilities and your carrier or internet service. GMA is not responsible for performance failures caused by network outages, coverage gaps, carrier failures, or power outages beyond GMA's control. Because alerts and communications depend on power and connectivity, you should not rely on the Services as your only means of summoning help. See Section 13 (Important Safety Notice). You (or the Facility, as applicable) are responsible for keeping devices charged and powered, keeping GMA-provided devices within carrier coverage areas, maintaining any internet or network service you supply yourself, permitting installation of updates GMA makes available, and promptly reporting device damage or malfunction; alerts and features may not function if these responsibilities are not met. GMA is responsible for maintaining the cellular service plan on GMA-provided devices as described in Section 3(b).
​
9. MONITORING; USAGE DATA; COMMUNICATIONS CONSENT
​
We may monitor and collect configuration, performance, and usage data relating to your use of the Services ("Usage Data") to deliver the Services (tracking entitlements, providing support, monitoring performance, integrity, and stability, and preventing or addressing service and security issues) and to improve our products and your experience. You must not interfere with that monitoring. We access Your Submissions and Health Data only as necessary to provide the Services, as permitted by Section 10(c), or as required by law — and always consistent with HIPAA and our Privacy Policy. Usage Data used for product improvement and analytics is de-identified or aggregated; identifiable data remains governed by HIPAA and the Privacy Policy, and is never sold (Section 11(c)). Calls, video sessions, and messages transmitted through the Services (including Compass Care Calling) may be monitored or recorded for care-delivery, quality, safety, and support purposes as described in the Privacy Policy; by using those features you consent to such monitoring and recording, and where the law of a participant's state requires all-party consent, GMA will provide notice or obtain consent from all participants before recording. By providing a telephone number, you consent to receive operational, support, safety, alert, and account-related calls and text messages from GMA at that number, including messages sent using automated technology or prerecorded voice; message and data rates may apply; consent to marketing messages, if ever requested, is separate and is not a condition of any purchase; and you may opt out of non-essential messages at any time by following the instructions in the message or contacting us, understanding that opting out of safety and alert messages may limit the functionality of the Services.
​
10. YOUR SUBMISSIONS
​
a. Communication and Sharing. The Services allow you to communicate and share Content with other Users ("Your Submissions") and to view Content shared by other Users ("User Submissions"). We honor the sharing and visibility choices you make where settings are available, including an End User's choices about who is in their contacts. Your Submissions are shared with your Facility and the Caregivers and contacts you (or your LAR, within their authority) designate, as configured for your Account. GMA safeguards Your Submissions in accordance with this Agreement, HIPAA where applicable, and our Privacy Policy. Please understand that GMA cannot control what authorized recipients do with information after they receive it outside the Platform, and you should exercise judgment about what you share.
b. Ownership; License to GMA. You retain all Intellectual Property Rights in Your Submissions and represent that you have the rights needed to share them. You grant GMA a non-exclusive, worldwide, royalty-free license to host, store, reproduce, display, transmit, and adapt Your Submissions solely as necessary to operate, provide, secure, and support the Services, sublicensable only to GMA's contracted service providers bound by obligations at least as protective as this Agreement. This license ends when you delete the Content or close your Account, except for copies retained in routine backups or as retention is required by law or described in the Privacy Policy.
c. Required Access and Disclosure. We may access, preserve, and disclose Content, Health Data, or related information where we reasonably believe it necessary to (i) comply with applicable law, regulation, legal process, or governmental request; (ii) enforce this Agreement, including investigating potential violations; (iii) detect, prevent, or address fraud, security, or technical issues; or (iv) respond to your support requests — in each case consistent with HIPAA's requirements, including minimum-necessary standards, and our Privacy Policy.
d. Use of Others' Data. Except as permitted by a User, you may not Process another User's Submissions outside the Services' platform and interfaces. Each such User is a third-party beneficiary of this Section 10(d).
​
11. HEALTH DATA; HIPAA; PROTECTED HEALTH INFORMATION
​
a. GMA's HIPAA Posture. GMA operates as a covered entity and/or as a business associate, as applicable to the function being performed, under the Health Insurance Portability and Accountability Act ("HIPAA"). Protected Health Information ("PHI") created, received, maintained, or transmitted through the Services is governed by HIPAA, our Privacy Policy, our Notice of Privacy Practices ("NPP"), and the Business Associate Agreements GMA maintains with its facility partners, payers' agents, and technology vendors as applicable. If this Agreement conflicts with HIPAA, the NPP, or an applicable BAA with respect to PHI, HIPAA, the NPP, and the BAA control.
b. Your Health Data Choices. The Platform and its Integrated Services Process certain Health Data. Your Health Data is shared with your Facility and with the Caregivers and contacts designated for your Account, as configured by you or your LAR within their authority. If you do not want a category of Health Data Processed, do not enable — or ask us to disable — the features and Integrated Services that collect it; we will explain the care and safety functions that will be affected before making changes.
c. No Sale; No Marketing.
OUR PROMISE: We will never sell your information, and we will never use or disclose your information — including de-identified information — for third-party marketing, advertising, data brokering, or commercial AI training, under any circumstances. This promise is contractual and is detailed in our Privacy Policy and Notice of Privacy Practices, including its application to any successor of GMA's business.
d. No Waiver of Rights. Nothing in this Agreement waives, limits, or conditions any right you hold under HIPAA (including access, amendment, accounting of disclosures, restriction requests including the self-pay restriction, and the right to revoke authorizations) or under applicable state health-privacy law.
e. Security Incidents. GMA maintains administrative, physical, and technical safeguards as described in the Privacy Policy; GMA's cloud-hosting environments (production and staging alike) and its cellular carrier partners operate under Business Associate Agreements where PHI is involved, and will respond to security incidents and provide breach notifications as required by HIPAA, the HITECH Act, and applicable state breach-notification laws.
​
12. NORA CAREGIVER INTELLIGENCE (AI FEATURES)
​
a. What Nora Is. Nora Caregiver Intelligence ("Nora") uses artificial intelligence to provide caregiver support, summaries, reminders, prompts, and insights drawn from information in the MyCompass System. The Services will indicate when you are interacting with an AI feature, and you may always request contact with a human at GMA.
b. Informational Only; Human Oversight. AI-generated output may be inaccurate, incomplete, or out of date. Nora's outputs are informational tools for caregivers and care teams. They are not medical advice, diagnosis, or treatment; they are not a substitute for the judgment of licensed professionals or for reading the underlying records; and they must be reviewed by a human before being relied on for any care, health, safety, medication, or legal decision. Nora does not take autonomous clinical actions. GMA does not guarantee the accuracy, completeness, or fitness for any purpose of AI-generated content, and users remain solely responsible for decisions made or actions taken based on AI-generated output.
c. Data Practices. Nora Processes data in accordance with HIPAA and our Privacy Policy. GMA does not use identifiable client data to train commercial AI models and does not sell data used by or generated through Nora (Section 11(c)).
d. Fairness. GMA monitors its AI features to identify and address discriminatory or biased performance, consistent with Section 16 (Nondiscrimination) of this Agreement and Section 1557 of the Affordable Care Act.
​
13. IMPORTANT SAFETY NOTICE
​
IF YOU BELIEVE THERE IS A MEDICAL OR OTHER EMERGENCY, CALL 911 (OR YOUR LOCAL EMERGENCY NUMBER) IMMEDIATELY. DO NOT RELY ON THE MYCOMPASS SYSTEM TO SUMMON EMERGENCY HELP.
a. Not a PERS; Not for Crisis Management. The MyCompass System is not a Personal Emergency Response System, may not be used for crisis management, and is not a substitute for in-person or professional monitoring of anyone with serious health conditions or disabilities. Alerting and monitoring features are supplemental safety tools whose operation depends on device power, configuration, and network connectivity, and they may fail, be delayed, or be unavailable.
b. No Diagnosis or Treatment by the Platform. The MyCompass software platform does not diagnose or treat health conditions, and information and reports generated by the Services are not a substitute for consultation, evaluation, or treatment by licensed medical professionals, or for good personal judgment about one's own condition. No feature of the Platform — including alerts, sensor data, Nora, or support check-ins — constitutes clinical surveillance or a substitute for care by the End User's own providers.
c. Integrated Medical Devices. Certain Integrated Services include devices that are FDA-cleared medical devices (for example, certain physiologic monitoring sensors). Those devices are provided and used in accordance with their FDA clearance, labeling, and manufacturer instructions. Except for such devices as labeled, the Services are not a medical device.
d. Imminent Harm; Mandatory Reporting. If GMA personnel reasonably believe that an End User or another person faces a risk of imminent harm — including statements or indications of self-harm, harm to others, or a medical emergency — GMA may, in its discretion, contact emergency services, the End User's designated Caregivers or Facility, or other appropriate persons. GMA may also disclose information to the extent required or permitted by law where its personnel have reason to suspect abuse, neglect, or exploitation of a child or of an elderly or vulnerable adult, including reports to and cooperation with child protective services, adult protective services, and law enforcement. Disclosures under this subsection are made consistent with HIPAA (45 C.F.R. § 164.512) and applicable state mandatory-reporting laws, and do not create a duty on GMA's part to monitor for, detect, or prevent harm (Sections 13(a) and 15(b)).
​
14. NOT A REPLACEMENT FOR PERSONAL CARE
​
The MyCompass System is a tool meant to enhance relationships and support — not to replace the personal care and attention provided by family, caregivers, and professionals.
​
15. MONTHLY SUPPORT SERVICES; BILLING AND PAYER COMPLIANCE
​
a. Monthly Support. As part of a MyCompass Subscription, End Users, their Caregivers, and their care teams receive ongoing and monthly support from GMA's support team, whose members include personnel with backgrounds in technical support, emergency management, and occupational therapy. Monthly support may include, as needed or requested: technical support and troubleshooting; check-ins; assistance identifying, obtaining, and configuring additional equipment; and a review of the End User's technology setup and use environment as they relate to safe and effective use of the Services (a "Safety Assessment"). GMA does not guarantee support availability or response times unless expressly stated in a separate written agreement.
b. Nature of Support; Suggestions Are Voluntary. All support services are supportive and consultative. They offer suggestions and education intended to improve the End User's independence and quality of life and the effectiveness of the care team. Whether to adopt any suggestion is entirely the decision of the End User, their LAR, and their care team, and GMA is not responsible for decisions to adopt, modify, or decline a suggestion. Support services — including check-ins conducted by personnel with occupational therapy licensure or background, and Safety Assessments — are not occupational therapy evaluation or treatment, are not clinical or medical evaluations, are not delivered under a plan of care, and do not create a therapeutic or treatment relationship, a duty to diagnose, or a duty to monitor the End User's condition or the data generated by the Services between support contacts. A Safety Assessment is an informational review relating to use of the technology; it is not a guarantee of safety and does not replace home-safety, clinical, or environmental evaluations by the End User's own providers. GMA's support personnel facilitate GMA's response to device, service, and alert escalations in accordance with configured protocols; this escalation support is not an emergency medical dispatch or response service, and it does not make the Services a Personal Emergency Response System (Section 13). If any interaction surfaces a potential clinical concern, GMA will recommend that the End User (or their LAR or Caregiver) contact the End User's own providers, and, in an emergency, call 911.
c. Additional Equipment. Equipment GMA supplies or recommends is subject to the manufacturer's terms, warranties, and labeling (and, for FDA-cleared devices, Section 13(c)). Charges for additional equipment, if any, are stated in your order form or service authorization and are subject to Section 15(d).
d. Government Program Beneficiaries. If the Services or any equipment are covered by Medicaid (including a Medicaid HCBS waiver), TRICARE, or another government health program, GMA will not charge you more than the amounts permitted by that program for covered items and services, and will not bill you for covered items and services beyond authorized cost-sharing. You will be charged for non-covered items or services only if you (or your LAR) received advance written notice that the item or service is not covered, with its cost, and agreed in writing to pay.
e. Financial Responsibility. Subscriptions may be funded by a Facility, by a government program or waiver, or privately by you or your family, as stated in your order form or service authorization. Support services under this Section — including check-ins and Safety Assessments — are included in the Subscription and are not separately billed to you or to any payer as therapy, clinical, or medical services. Termination of this Agreement does not waive amounts lawfully due for Services already provided, but Section 15(d) always controls what a government-program beneficiary may be charged.
f. No Tying. Equipment suggestions are options, not requirements: GMA does not condition access to the Services on the purchase of additional equipment, except where an item is technically necessary for a feature you request or required by a payer or program as a condition of coverage.
​
16. NONDISCRIMINATION; ACCESSIBILITY
​
GMA does not discriminate on the basis of race, color, national origin, sex, age, or disability in its programs and services, consistent with Section 1557 of the Affordable Care Act and other applicable civil-rights laws. GMA provides auxiliary aids and services and language assistance free of charge to ensure effective communication, including accessible formats of this Agreement and the acceptance process described in Section 1(a).
​
17. WARRANTIES; DISCLAIMERS
​
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, AND EXCEPT AS PROVIDED IN SECTIONS 13(c) AND 15(a):
a. THE TECHNOLOGY SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE," AND WE AND OUR LICENSORS AND SUPPLIERS DISCLAIM ALL WARRANTIES AND CONDITIONS, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT.
b. WE DO NOT WARRANT THAT DEFECTS WILL BE CORRECTED OR THAT THE SERVICES WILL MEET YOUR REQUIREMENTS, BE COMPATIBLE WITH YOUR DEVICE OR NETWORK, BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR-FREE, OR BE ACCURATE OR RELIABLE. NO ORAL OR WRITTEN INFORMATION OBTAINED FROM US OR THROUGH THE SERVICES CREATES ANY WARRANTY.
c. WE DO NOT WARRANT, ENDORSE, OR ASSUME RESPONSIBILITY FOR ANY INDEPENDENT SERVICE (SECTION 7(d)) OR ANY PRODUCT OR SERVICE ADVERTISED OR OFFERED BY A THIRD PARTY OUTSIDE THE MYCOMPASS SYSTEM, AND WE ARE NOT A PARTY TO TRANSACTIONS BETWEEN YOU AND SUCH THIRD PARTIES.
d. HEALTH DATA AND WELLNESS INFORMATION PRESENTED THROUGH THE SERVICES MAY BE UNAVAILABLE, INACCURATE, OR INCOMPLETE, AND — EXCEPT FOR DATA PRODUCED BY AN FDA-CLEARED DEVICE OPERATING PER ITS LABELING — IS NOT INTENDED TO MATCH THE ACCURACY OF MEDICAL OR SCIENTIFIC MEASUREMENT DEVICES.
e. THIS SECTION DOES NOT LIMIT GMA'S OBLIGATIONS UNDER HIPAA OR ANY PAYER AGREEMENT, AND DOES NOT LIMIT ANY WARRANTY OR RIGHT THAT CANNOT BE DISCLAIMED UNDER THE LAW OF YOUR STATE. SOME JURISDICTIONS DO NOT ALLOW CERTAIN WARRANTY DISCLAIMERS, SO SOME OF THE ABOVE MAY NOT APPLY TO YOU.
​
18. LIMITATION OF LIABILITY
​
TO THE FULLEST EXTENT PERMITTED BY LAW: (a) GMA AND ITS AFFILIATES WILL NOT BE LIABLE IN CONNECTION WITH THIS AGREEMENT FOR LOST PROFITS OR BUSINESS OPPORTUNITIES, LOSS OF DATA, OR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES; AND (b) GMA'S TOTAL LIABILITY IN CONNECTION WITH THIS AGREEMENT WILL NOT EXCEED THE GREATER OF (i) THE TOTAL FEES PAID OR PAYABLE BY YOU TO GMA FOR THE SERVICES IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM AND (ii) US $1,000. THE LIMITATIONS IN THIS SECTION APPLY TO CLAIMS BASED ON GMA'S ORDINARY NEGLIGENCE, AND THE PARTIES INTEND THIS SECTION TO BE CLEAR, UNAMBIGUOUS, UNMISTAKABLE, AND CONSPICUOUS UNDER MISSOURI LAW. THIS SECTION DOES NOT — AND UNDER MISSOURI LAW CANNOT — LIMIT LIABILITY FOR GROSS NEGLIGENCE, RECKLESSNESS, OR INTENTIONAL MISCONDUCT, DOES NOT LIMIT LIABILITY FOR DEATH OR BODILY INJURY TO THE EXTENT SUCH LIABILITY CANNOT LAWFULLY BE LIMITED, AND DOES NOT LIMIT ANY LIABILITY THAT CANNOT BE LIMITED UNDER THE LAW OF YOUR STATE OF RESIDENCE.
​
19. INDEMNIFICATION
​
You agree to indemnify and hold harmless GMA, its affiliates, and their respective officers, directors, employees, and agents from third-party claims, damages, and expenses (including reasonable attorneys' fees) to the extent arising from (a) your violation of this Agreement or of applicable law, (b) your misuse of the Services, or (c) your violation of a third party's rights, including intellectual-property or privacy rights. This obligation does not apply to the extent a claim arises from GMA's negligence, willful misconduct, or breach of this Agreement, and does not apply where prohibited by law.
​
20. TERMINATION
​
a. Your Right to Terminate. You may stop using the Services at any time and may terminate this Agreement immediately on written notice to us. Financial responsibility after termination is governed by Section 15.
b. Caregivers. If you are a Caregiver or contact, this Agreement terminates automatically as to you when you are removed as a designated member for all End Users (unless you are also an End User with an active Subscription).
c. End Users. If you are an End User, this Agreement terminates automatically upon your death or the termination or expiration of your Subscription. Upon death, disposition of your data follows our Privacy Policy, and your personal representative (appointed under Chapter 473, RSMo, or the law of your state of residence) may exercise applicable rights under HIPAA and state law.
d. Termination for Cause. Either party may terminate this Agreement effective immediately on written notice if the other party (i) breaches this Agreement and fails to cure within 30 days of notice, or (ii) commits a material breach that cannot be cured. GMA may also suspend or terminate an Account, or decline to open one, where reasonably necessary to address abusive, threatening, harassing, illegal, or unsafe conduct directed at GMA personnel, other Users, or the Services — subject to the notice and review process in Section 5(c) and, for End Users, the transition protections in Section 20(e).
e. Funder Termination; Transition. If a Facility or other funding party ends its funding of your Subscription or reallocates it, GMA will provide you (or your LAR) reasonable advance notice where practicable, a period of at least 30 days to export Your Submissions and Health Data as described in the Privacy Policy — in a common machine-readable or portable format such as CSV, PDF, or JSON where technically feasible — and reasonable transition support — recognizing that for many End Users the Platform is a primary means of communication.
f. Effect of Termination; Survival. Upon termination for any reason, you must stop using the Services, and deletion of Your Submissions and Health Data remaining in the Services occurs as specified in the Privacy Policy. Rather than requiring return of a GMA-provided device, GMA will release the device to you (or as your order form directs): GMA will deactivate and remove its services from the device — including mobile device management, cybersecurity and content-filtering software, GMA software licenses, and cellular data service — and the device will be reset and wiped. THE WIPE MAY PERMANENTLY ERASE ALL DATA STORED ON THE DEVICE, INCLUDING MESSAGES, PHOTOS, AND OTHER CONTENT — REQUEST AN EXPORT OF ANYTHING YOU WANT TO KEEP, AS DESCRIBED IN THE PRIVACY POLICY AND SECTION 20(e), BEFORE THE RELEASE. Upon release, the device is provided to you AS IS, without any warranty from GMA; it is no longer part of the Services; all GMA safety, alerting, monitoring, communication, filtering, security, connectivity, and support features permanently cease — including, for minor End Users, the parental controls described in Section 2(d) — and GMA has no responsibility for the device or its subsequent use. Sections 10(b)–(d), 11, 13, 14, 15, 17, 18, 19, 20(f), 21, 22, and 23 survive termination.
​
21. DISPUTE RESOLUTION; BINDING ARBITRATION
​
a. Agreement to Arbitrate. YOU AND GMA AGREE THAT ANY CLAIM, DISPUTE, OR CONTROVERSY (WHETHER IN CONTRACT, TORT, OR OTHERWISE, AND INCLUDING STATUTORY, CONSUMER-PROTECTION, COMMON-LAW, INJUNCTIVE, AND EQUITABLE CLAIMS) ARISING FROM OR RELATING TO THE SERVICES OR THIS AGREEMENT WILL BE RESOLVED EXCLUSIVELY BY FINAL AND BINDING ARBITRATION, RATHER THAN IN COURT OR BEFORE A JURY, EXCEPT AS PROVIDED IN THIS SECTION 21. RIGHTS AVAILABLE IN COURT MAY BE UNAVAILABLE OR LIMITED IN ARBITRATION. You acknowledge that you had the opportunity to review this Agreement, to ask questions, and to obtain assistance — including the accessible-format and LAR assistance described in Sections 1(a) and 2 — before accepting.
b. Your Right to Opt Out. YOU MAY OPT OUT OF THIS ARBITRATION AGREEMENT ENTIRELY, WITH NO EFFECT ON YOUR SERVICES, by sending written notice of your decision to the address in Section 22(e) (or by email to info@graymattersalliance.com) within 30 days after you first accept this Agreement. If you opt out, disputes will be resolved in court, and the class-action waiver in Section 21(f) will not apply to you. For disputes proceeding in court, the parties consent to the jurisdiction of the state courts of St. Charles County, Missouri, and the United States District Court for the Eastern District of Missouri — except that this consent does not override any non-waivable right you hold to bring or defend a claim in the courts of your state of residence.
c. Exceptions. Either party may bring a qualifying individual claim in small-claims court at any time. Nothing in this Section prevents you from filing a complaint with any government agency — including the HHS Office for Civil Rights, your state Medicaid agency or attorney general, or the Defense Health Agency — or prevents that agency from seeking relief on your behalf.
d. Procedure. The arbitration will be administered by the American Arbitration Association ("AAA") under its Consumer Arbitration Rules then in effect, as modified by this Section 21. The Federal Arbitration Act (9 U.S.C. § 1 et seq.) governs the interpretation and enforcement of this Section; to the extent not preempted, the Missouri Uniform Arbitration Act (§§ 435.350–435.470, RSMo) applies, and the notice required by § 435.460, RSMo appears adjacent to the signature block of this Agreement. Filing, administration, and arbitrator fees are allocated as provided in the AAA Consumer Arbitration Rules; GMA will pay those fees to the extent the AAA Rules or applicable law require, and GMA will not seek its attorneys' fees or costs from you in arbitration except where the arbitrator finds a claim frivolous or brought in bad faith under applicable law. The arbitrator has exclusive authority to resolve disputes about the arbitrability or enforceability of this arbitration provision (except as provided in Section 21(f)), may grant any relief available in court, and any award may be entered as a judgment in a court of competent jurisdiction. In-person hearings, if required, will occur in or around St. Louis, Missouri, unless the arbitrator determines otherwise or the parties agree to remote proceedings; you may elect to proceed by telephone, video, or written submissions.
e. Individual Basis. Arbitration will proceed on an individual basis. NEITHER YOU NOR GMA MAY JOIN OR CONSOLIDATE CLAIMS WITH THOSE OF OTHER USERS OR PARTICIPATE IN ANY CLAIM AS A CLASS REPRESENTATIVE, CLASS MEMBER, OR PRIVATE ATTORNEY GENERAL. The arbitrator may not consolidate more than one person's claims or preside over any class or representative proceeding.
f. Class-Waiver Review; Severability. Any challenge to the enforceability of the class-arbitration waiver may be decided only by a court of competent jurisdiction. If any provision of this arbitration agreement is found unenforceable, that provision will be severed and the remainder enforced — except that if the class-arbitration waiver is found unenforceable as to a particular claim, that claim (and only that claim) will proceed in court.
​
22. GENERAL
​
a. Subcontracting. We may subcontract our obligations under this Agreement, provided that any subcontractor that will create, receive, maintain, or transmit PHI is bound by a Business Associate Agreement or equivalent HIPAA-compliant contract. We remain responsible to you for our subcontractors' performance of our obligations.
b. U.S. Services; Export; Sanctions. The Services are offered for use in the United States and its territories; GMA makes no representation that the Services are appropriate or available for use elsewhere. You will not directly or indirectly export or re-export (including any deemed export or re-export) the Services or associated software, technical data, or information in violation of applicable law, and you represent that you are not identified on any U.S. government sanctions or restricted-party list and are not located in a country or region subject to comprehensive U.S. sanctions.
c. Governing Law. The laws of the State of Missouri, excluding conflict-of-laws rules, govern this Agreement and any dispute relating to it or the Services — provided that this choice of law does not deprive you of non-waivable protections of the consumer-protection or health-privacy laws of the state where you reside, and nothing in this Agreement waives or limits any non-waivable right under the Missouri Merchandising Practices Act (Chapter 407, RSMo) for Missouri residents. The U.N. Convention on Contracts for the International Sale of Goods does not apply.
d. Recovery of Expenses. This Agreement does not shift attorneys' fees or costs to you except as expressly permitted by Section 21(d) or required by law. Where a statute gives you a right to recover your fees if you prevail, nothing here limits that right.
e. All legal notices will be sent to McCarthy, Leonard, & Kraemmer 825 Maryville Centre Dr #300 Chesterfield Missouri 63017 We may update our notice address by posting on our website.
f. Force Majeure. Except for payment obligations, neither party is liable for delay or failure to perform due to causes beyond its reasonable control, including labor disputes, utility, internet backbone, or telecommunications failures, cloud-provider or hosting outages, cyberattacks, ransomware, or other cybersecurity incidents not caused by that party's failure to maintain reasonable safeguards, natural disasters, embargoes, riots, acts or orders of government, terrorism, or war.
g. Assignment. You may not assign your rights or delegate your obligations under this Agreement without our prior written consent; any purported assignment in violation of this subsection is void, and no assignment relieves you of your obligations. GMA may assign this Agreement in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets, provided the successor assumes GMA's obligations under this Agreement — including the commitments in Section 11(c), which bind any successor as described in the Privacy Policy.
h. Third-Party Rights. Except as set forth in Section 10(d), this Agreement is for the sole benefit of the parties and their respective successors and permitted assigns, and confers no rights or remedies on any other person.
i. www.graymattersalliance.com/privacypolicy and the Documentation atwww.graymattersalliance.com/mycompasstermsofuse].
j. Severability; No Waiver. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in force to the extent feasible. A party's failure to enforce a provision is not a waiver of it.
​
23. DEFINITIONS
​
"Account" means your GMA/MyCompass System account, whether as an End User, a Caregiver, or both.
"Caregiver" means a person designated by an End User (or the End User's LAR, within the LAR's authority) who may communicate with the End User via the Services and may access the End User's Content and Health Data to the extent designated. End Users may modify or change their designated Caregivers at any time, for any reason, and GMA is not liable for an End User's designation choices.
"Content" means any data, including text, sound, video, image files, software, or other information.
"Documentation" means the description of the Services published by GMA at the URL identified in Section 22(i).
"End User" means the individual client — including a Senior or a person with a disability — who is the primary user receiving GMA's supportive and assistive technology services. References to "Senior" in GMA materials refer to an End User.
"Facility" means the End User's living facility, independent living agency, assisted living facility, provider agency, or other organization that has purchased or authorized the End User's Subscription.
"Feedback" means feedback or suggestions about the Services that you provide to GMA. If you provide Feedback, GMA may use it without obligation to you, and you assign to GMA all right, title, and interest in it — excluding any personal or health information contained in it, which remains governed by the Privacy Policy.
"Health Data" means End User data Processed through the Services relating to health, wellness, or safety, including (i) use of the Services; (ii) physiologic measurements such as body temperature, blood pressure, heart rate, glucose level, and respiratory rate; (iii) activity level; (iv) nutrition and hydration; (v) sleep routines; (vi) responses to prompts and questionnaires soliciting mental-health and personal-health information; and (vii) pill and medication reminder/dispenser data. Health Data that constitutes PHI is governed by Section 11.
"Intellectual Property Rights" means all patent, copyright, trademark, trade-secret, database, moral, and other intellectual-property rights, registered or unregistered, throughout the world.
"Legally Authorized Representative (LAR)" has the meaning given in Section 2(b).
"Process" means any operation performed on data, such as accessing, obtaining, storing, transmitting, using, maintaining, disclosing, or disposing of it.
"Subscription" means an End User's entitlement to use the Services under this Agreement, on monthly or other terms, funded by a Facility, a government program or waiver, or privately, as stated in the applicable order form or service authorization.
"Term" means the period beginning on your acceptance of this Agreement and ending on its termination under Section 20.
"Users" means End Users, Caregivers, contacts, and Facilities using the Services.
GMA owns and retains all right, title, and interest in and to the Services and related GMA software, including improvements and derivative works, and all Intellectual Property Rights in them, together with de-identified and aggregate Usage Data as described in Section 9. Your rights are limited to those expressly granted in this Agreement.
​
